Lucene search

K
cve[email protected]CVE-2024-29093
HistoryMar 19, 2024 - 5:15 p.m.

CVE-2024-29093

2024-03-1917:15:11
CWE-352
web.nvd.nist.gov
39
cve-2024-29093
cross-site request forgery
csrf
tobias conrad builder
woocommerce
reviewshort

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

9.3 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Cross-Site Request Forgery (CSRF) vulnerability in Tobias Conrad Builder for WooCommerce reviews shortcodes – ReviewShort.This issue affects Builder for WooCommerce reviews shortcodes – ReviewShort: from n/a through 1.01.3.

Affected configurations

Vulners
Node
tobias_conradbuilder_for_woocommerce_reviews_shortcodes_–_reviewshortRange1.01.3

CNA Affected

[
  {
    "collectionURL": "https://wordpress.org/plugins",
    "defaultStatus": "unaffected",
    "packageName": "woo-product-reviews-shortcode",
    "product": "Builder for WooCommerce reviews shortcodes – ReviewShort",
    "vendor": "Tobias Conrad",
    "versions": [
      {
        "changes": [
          {
            "at": "1.01.4",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "1.01.3",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

9.3 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Related for CVE-2024-29093