Cross-site request forgery (CSRF) vulnerability exists in Ninja Forms prior to 3.4.31. If a website administrator views a malicious page while logging in, unintended operations may be performed.
References
| Link | Resource |
|---|---|
| https://jvn.jp/en/jp/JVN50361500/ | Third Party Advisory |
| https://ninjaforms.com/ | Product |
| https://wordpress.org/plugins/ninja-forms/ | Product |
| https://jvn.jp/en/jp/JVN50361500/ | Third Party Advisory |
| https://ninjaforms.com/ | Product |
| https://wordpress.org/plugins/ninja-forms/ | Product |
Configurations
History
No history.
Information
Published : 2024-04-11 03:15
Updated : 2025-04-08 15:17
NVD link : CVE-2024-25572
Mitre link : CVE-2024-25572
CVE.ORG link : CVE-2024-25572
JSON object : View
Products Affected
ninjaforms
- ninja_forms
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
