#VU25005 Cross-site request forgery in Htaccess by BestWebSoft - CVE-2020-8658
Published: February 6, 2020
Htaccess by BestWebSoft
BestWebSoft
Description
The vulnerability allows a remote attacker to perform cross-site request forgery attacks.
The vulnerability exists within the "htccss_nonce_name" flag due to insufficient validation of the HTTP request origin in "wp-admin/admin.php?page=htaccess.php&action=htaccess_editor". A remote attacker can trick the victim to visit a specially crafted web page that modifies the .htaccess file and perform arbitrary actions on behalf of the victim on the vulnerable website.