CVE-2024-24837

Score

4.3 Medium

Date publish

21-02-2024

Versiones afectadas

  • No versions found.

Description

Cross-Site Request Forgery (CSRF) vulnerability in Frédéric GILLES FG PrestaShop to WooCommerce, Frédéric GILLES FG Drupal to WordPress, Frédéric GILLES FG Joomla to WordPress.This issue affects FG PrestaShop to WooCommerce: from n/a through 4.44.3; FG Drupal to WordPress: from n/a through 3.67.0; FG Joomla to WordPress: from n/a through 4.15.0.

References

Metrics

cvssMetricV31
sourceaudit@patchstack.com
typeSecondary
version3.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
baseScore4.3
baseSeverityMEDIUM
attackVectorNETWORK
attackComplexityLOW
privilegesRequiredNONE
userInteractionREQUIRED
scopeUNCHANGED
confidentialityImpactNONE
integrityImpactLOW
availabilityImpactNONE
exploitabilityScore2.8
impactScore1.4
Scroll al inicio