All the vulnerabilites related to Tips and Tricks HQ - Software License Manager
jvndb-2021-000066
Vulnerability from jvndb
Published
2021-07-08 13:45
Modified
2021-07-08 13:45
Severity ?
Summary
WordPress Plugin "Software License Manager" vulnerable to cross-site request forgery
Details
WordPress Plugin "Software License Manager" provided by Tips and Tricks HQ contains a cross-site request forgery vulnerability (CWE-352). Koken Tokuda of Cryptography Laboratory, Department of Information and Communication Engineering, Tokyo Denki University. reported this vulnerability to the developer and coordinated on his own. After coordination was completed, JPCERT/CC published respective advisories in order to notify users of this vulnerability.
Impacted products
Show details on JVN DB website


{
  "@rdf:about": "https://jvndb.jvn.jp/en/contents/2021/JVNDB-2021-000066.html",
  "dc:date": "2021-07-08T13:45+09:00",
  "dcterms:issued": "2021-07-08T13:45+09:00",
  "dcterms:modified": "2021-07-08T13:45+09:00",
  "description": "WordPress Plugin \"Software License Manager\" provided by Tips and Tricks HQ contains a cross-site request forgery vulnerability (CWE-352).\r\n\r\nKoken Tokuda of Cryptography Laboratory, Department of Information and Communication Engineering, Tokyo Denki University. reported this vulnerability to the developer and coordinated on his own.\r\nAfter coordination was completed, JPCERT/CC published respective advisories in order to notify users of this vulnerability.",
  "link": "https://jvndb.jvn.jp/en/contents/2021/JVNDB-2021-000066.html",
  "sec:cpe": {
    "#text": "cpe:/a:tips_and_tricks_hq:software_license_manager",
    "@product": "Software License Manager",
    "@vendor": "Tips and Tricks HQ",
    "@version": "2.2"
  },
  "sec:cvss": [
    {
      "@score": "2.6",
      "@severity": "Low",
      "@type": "Base",
      "@vector": "AV:N/AC:H/Au:N/C:N/I:P/A:N",
      "@version": "2.0"
    },
    {
      "@score": "4.3",
      "@severity": "Medium",
      "@type": "Base",
      "@vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
      "@version": "3.0"
    }
  ],
  "sec:identifier": "JVNDB-2021-000066",
  "sec:references": [
    {
      "#text": "https://jvn.jp/en/jp/JVN89054582/index.html",
      "@id": "JVN#89054582",
      "@source": "JVN"
    },
    {
      "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20782",
      "@id": "CVE-2021-20782",
      "@source": "CVE"
    },
    {
      "#text": "https://nvd.nist.gov/vuln/detail/CVE-2021-20782",
      "@id": "CVE-2021-20782",
      "@source": "NVD"
    },
    {
      "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
      "@id": "CWE-352",
      "@title": "Cross-Site Request Forgery(CWE-352)"
    }
  ],
  "title": "WordPress Plugin \"Software License Manager\" vulnerable to cross-site request forgery"
}

cve-2021-20782
Vulnerability from cvelistv5
Published
2021-07-14 01:20
Modified
2024-08-03 17:53
Severity ?
Summary
Cross-site request forgery (CSRF) vulnerability in Software License Manager versions prior to 4.4.6 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
Impacted products
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-03T17:53:22.376Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_refsource_MISC",
              "x_transferred"
            ],
            "url": "https://wordpress.org/plugins/software-license-manager/"
          },
          {
            "tags": [
              "x_refsource_MISC",
              "x_transferred"
            ],
            "url": "https://www.tipsandtricks-hq.com/software-license-manager-plugin-for-wordpress"
          },
          {
            "tags": [
              "x_refsource_MISC",
              "x_transferred"
            ],
            "url": "https://jvn.jp/en/jp/JVN89054582/index.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Software License Manager",
          "vendor": "Tips and Tricks HQ",
          "versions": [
            {
              "status": "affected",
              "version": "versions prior to 4.4.6"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "Cross-site request forgery (CSRF) vulnerability in Software License Manager versions prior to 4.4.6 allows remote attackers to hijack the authentication of administrators via unspecified vectors."
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Cross-site request forgery",
              "lang": "en",
              "type": "text"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2021-07-14T01:20:28",
        "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "shortName": "jpcert"
      },
      "references": [
        {
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://wordpress.org/plugins/software-license-manager/"
        },
        {
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://www.tipsandtricks-hq.com/software-license-manager-plugin-for-wordpress"
        },
        {
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://jvn.jp/en/jp/JVN89054582/index.html"
        }
      ],
      "x_legacyV4Record": {
        "CVE_data_meta": {
          "ASSIGNER": "vultures@jpcert.or.jp",
          "ID": "CVE-2021-20782",
          "STATE": "PUBLIC"
        },
        "affects": {
          "vendor": {
            "vendor_data": [
              {
                "product": {
                  "product_data": [
                    {
                      "product_name": "Software License Manager",
                      "version": {
                        "version_data": [
                          {
                            "version_value": "versions prior to 4.4.6"
                          }
                        ]
                      }
                    }
                  ]
                },
                "vendor_name": "Tips and Tricks HQ"
              }
            ]
          }
        },
        "data_format": "MITRE",
        "data_type": "CVE",
        "data_version": "4.0",
        "description": {
          "description_data": [
            {
              "lang": "eng",
              "value": "Cross-site request forgery (CSRF) vulnerability in Software License Manager versions prior to 4.4.6 allows remote attackers to hijack the authentication of administrators via unspecified vectors."
            }
          ]
        },
        "problemtype": {
          "problemtype_data": [
            {
              "description": [
                {
                  "lang": "eng",
                  "value": "Cross-site request forgery"
                }
              ]
            }
          ]
        },
        "references": {
          "reference_data": [
            {
              "name": "https://wordpress.org/plugins/software-license-manager/",
              "refsource": "MISC",
              "url": "https://wordpress.org/plugins/software-license-manager/"
            },
            {
              "name": "https://www.tipsandtricks-hq.com/software-license-manager-plugin-for-wordpress",
              "refsource": "MISC",
              "url": "https://www.tipsandtricks-hq.com/software-license-manager-plugin-for-wordpress"
            },
            {
              "name": "https://jvn.jp/en/jp/JVN89054582/index.html",
              "refsource": "MISC",
              "url": "https://jvn.jp/en/jp/JVN89054582/index.html"
            }
          ]
        }
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
    "assignerShortName": "jpcert",
    "cveId": "CVE-2021-20782",
    "datePublished": "2021-07-14T01:20:28",
    "dateReserved": "2020-12-17T00:00:00",
    "dateUpdated": "2024-08-03T17:53:22.376Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}