Lucene search

K
nvd[email protected]NVD:CVE-2023-32625
HistoryJul 21, 2023 - 1:15 a.m.

CVE-2023-32625

2023-07-2101:15:10
CWE-352
web.nvd.nist.gov
3
cve-2023-32625
csrf
ts webfonts
sakura 3.1.2
remote attacker
user authentication

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

AI Score

4.9

Confidence

High

EPSS

0.001

Percentile

30.7%

Cross-site request forgery (CSRF) vulnerability in TS Webfonts for SAKURA 3.1.2 and earlier allows a remote unauthenticated attacker to hijack the authentication of a user and to change settings by having a user view a malicious page.

Affected configurations

Nvd
Node
sakurats_webfontsRange3.1.2wordpress
VendorProductVersionCPE
sakurats_webfonts*cpe:2.3:a:sakura:ts_webfonts:*:*:*:*:*:wordpress:*:*

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

AI Score

4.9

Confidence

High

EPSS

0.001

Percentile

30.7%

Related for NVD:CVE-2023-32625