6.5
CVE-2023-2326
- EPSS 0.31%
- Veröffentlicht 27.06.2023 14:15:10
- Zuletzt bearbeitet 21.11.2024 07:58:23
- Erkennungen
Gravity Forms Google Sheet Connector < 1.3.5 - Access Code Update via CSRF
Gravity Forms Google Sheet Connector <= 1.3.4 - Cross-Site Request Forgery via verify_code_integation_new
The Gravity Forms Google Sheet Connector WordPress plugin before 1.3.5, gsheetconnector-gravityforms-pro WordPress plugin through 1.3.5 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack
Mögliche Gegenmaßnahme
GSheetConnector – Gravity Forms Google Sheets Connector – Real-Time Sync: Update to version 1.3.5, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gsheetconnector ≫ Gravity Forms Google Sheets Connector SwPlatform wordpress Version < 1.3.5
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
GSheetConnector – Gravity Forms Google Sheets Connector – Real-Time Sync
Version
*-1.3.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.31% | 0.221 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
|
https://wpscan.com/vulnerability/f922695a-b803-4edf-aadc-80c79d99bebb
https://www.wordfence.com/threat-intel/vulnerabilities/id/dea1e775-68b4-45e6-9d90-41e39d5d0dfd