8.8

CVE-2023-2329

Exploit

WooCommerce Google Sheet Connector < 1.3.6 - Access Code Update via CSRF

WooCommerce Google Sheet Connector < 1.3.6 - Cross-Site Request Forgery

The WooCommerce Google Sheet Connector WordPress plugin before 1.3.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack
Mögliche Gegenmaßnahme
GSheetConnector for WooCommerce – Send your Orders and Products to Google Sheet in Real-Time: Update to version 1.3.6, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GsheetconnectorWoocommerce Google Sheet Connector SwPlatformwordpress Version <= 1.3.4
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt GSheetConnector for WooCommerce – Send your Orders and Products to Google Sheet in Real-Time
Version *-1.3.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.367
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.