6.5

CVE-2023-2326

Exploit

Gravity Forms Google Sheet Connector < 1.3.5 - Access Code Update via CSRF

Gravity Forms Google Sheet Connector <= 1.3.4 - Cross-Site Request Forgery via verify_code_integation_new

The Gravity Forms Google Sheet Connector WordPress plugin before 1.3.5, gsheetconnector-gravityforms-pro WordPress plugin through 1.3.5 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack
Mögliche Gegenmaßnahme
GSheetConnector – Gravity Forms Google Sheets Connector – Real-Time Sync: Update to version 1.3.5, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gsheetconnector ≫ Gravity Forms Google Sheets Connector SwPlatform wordpress Version < 1.3.5
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt GSheetConnector – Gravity Forms Google Sheets Connector – Real-Time Sync
Version *-1.3.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.31% 0.221
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://wpscan.com/vulnerability/f922695a-b803-4edf-aadc-80c79d99bebb
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/dea1e775-68b4-45e6-9d90-41e39d5d0dfd
Third Party Advisory