Tag

#Cross-Site Request Forgery

articleCRITICAL 9.8

Critical Command Injection Vulnerability in Sustainable Irrigation Platform (SIP)

A critical command injection vulnerability (CVE-2026-58479) has been discovered in the Sustainable Irrigation Platform (SIP) through version 5.2.16. The vulnerability, located in the optional cli_control plugin, allows unauthenticated or cross-site request forgery attackers to execute arbitrary operating-system commands. This can be achieved by storing a malicious payload via the plugin's HTTP endpoint and triggering execution by activating the associated irrigation station, exploiting the absence of passphrase protection or the default passphrase 'opendoor'. The vulnerability has a CVSS score of 9.8 and is considered critical.

1 source
newsHIGH 8.6

Uni-CLI Vulnerability: Legacy HTTP MCP Transport Accepts Browser-Originated Localhost Requests

A vulnerability in Uni-CLI versions before 0.225.2 allows a malicious web page to send CORS simple POST requests to the local /mcp endpoint, potentially driving tools/call requests against the user's local Uni-CLI server. The issue has a CVSS score of 8.6 and is classified as high severity. To mitigate, upgrade to version 0.225.2 or later.

1 source
articleMEDIUM 4.3

CVE-2024-32110: Cross-Site Request Forgery Vulnerability in WpEvently Plugin

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the WpEvently plugin, affecting versions from n/a through 4.1.2. This vulnerability, tracked as CVE-2024-32110, has a severity score of 4.3 and allows attackers to perform Cross-Site Request Forgery attacks.

1 source