A Cross-Site Request Forgery (CSRF) leading to Cross-Site...
High severity
Unreviewed
Published
Jun 29, 2025
to the GitHub Advisory Database
•
Updated Jun 30, 2025
Description
Published by the National Vulnerability Database
Jun 29, 2025
Published to the GitHub Advisory Database
Jun 29, 2025
Last updated
Jun 30, 2025
A Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) vulnerability in the UCRM Client Signup Plugin (v1.3.4 and earlier) could allow privilege escalation if an Administrator is tricked into visiting a crafted malicious page. The plugin is disabled by default.
References