CVE-2013-4240 | Jeff Kreitner hms-testimonials up to 2.0.10 Advanced Settings cross-site request forgery (EDB-27531 / OSVDB-96107)
A vulnerability was found in Jeff Kreitner hms-testimonials up to 2.0.10 and classified as problematic. Affected by this issue is some unknown functionality of the component Advanced Settings. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2013-4240. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.