5.4

CVE-2023-2334

Easy Digital Downloads Google Sheet Connector < 1.6.6 - Access Code Update via CSRF

Easy Digital Downloads Google Sheet Connector <= 1.6.6 - Cross-Site Request Forgery to Access Code Update

The edd-google-sheet-connector-pro WordPress plugin before 1.4, Easy Digital Downloads Google Sheet Connector WordPress plugin before 1.6.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack
Mögliche Gegenmaßnahme
Edd Google Sheet Connector Pro: Update to version 1.4, or a newer patched version
GSheetConnector – Easy Digital Downloads Google Sheets Connector, EDD Export: Update to version 1.6.6, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Westerndeal ≫ Easy Digital Downloads Google Sheet Connector SwPlatform wordpress Version < 1.6.6
Gsheetconnector ≫ Edd Gsheetconnector SwEdition pro SwPlatform wordpress Version < 1.4
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt Edd Google Sheet Connector Pro
Version [*, 1.4)
SystemWordPress Plugin
≫
Produkt GSheetConnector – Easy Digital Downloads Google Sheets Connector, EDD Export
Version *-1.6.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.074
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CISA-ADP 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

https://wpscan.com/vulnerability/95562684-2bb1-46f0-838c-8501db6b43ed/
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/8222e290-1602-4f3d-b041-b3d24502dfee
Third Party Advisory