Input validation vulnerability in HQ Rental Software 1.5.29

A popular software used for renting called HQ Rental has a security issue. This issue, known as Cross-Site Request Forgery, affects all versions up to 1.5.29. The problem lies in the displaySettingsPage() function, specifically with the validation of a security measure called a nonce. This loophole allows hackers who are not logged in to make changes to important settings, which can lead to them gaining more control over the website. In order to do this, they would need to deceive the site administrator into clicking on a link.

Detected in:

HQ Rental Software open vulnerable versions: >= * <= 1.5.29

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.