Vulnerabilities > Themegrill > Themegrill Demo Importer
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-05-05 | CVE-2020-36334 | Cross-Site Request Forgery (CSRF) vulnerability in Themegrill Demo Importer themegrill-demo-importer before 1.6.3 allows CSRF, as demonstrated by wiping the database. | 8.8 |
2021-05-05 | CVE-2020-36333 | Missing Authentication for Critical Function vulnerability in Themegrill Demo Importer themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook. | 9.1 |