CVE-2024-24837
Description
Cross-Site Request Forgery (CSRF) vulnerability in Frédéric GILLES FG PrestaShop to WooCommerce, Frédéric GILLES FG Drupal to WordPress, Frédéric GILLES FG Joomla to WordPress.This issue affects FG PrestaShop to WooCommerce: from n/a through 4.44.3; FG Drupal to WordPress: from n/a through 3.67.0; FG Joomla to WordPress: from n/a through 4.15.0.
CWE
- CWE-352 — CWE-352 Cross-Site Request Forgery (CSRF)
Affected
- Frédéric GILLES / FG PrestaShop to WooCommerce — v=n/a ≤4.44.3 [affected]
- Frédéric GILLES / FG Drupal to WordPress — v=n/a ≤3.67.0 [affected]
- Frédéric GILLES / FG Joomla to WordPress — v=n/a ≤4.15.0 [affected]
CVSS
- 3.1 score=4.3 severity=MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
References
- https://patchstack.com/database/vulnerability/fg-drupal-to-wp/wordpress-fg-drupal-to-wordpress-plugin-3-67-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve vdb-entry
- https://patchstack.com/database/vulnerability/fg-prestashop-to-woocommerce/wordpress-fg-prestashop-to-woocommerce-plugin-4-44-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve vdb-entry
- https://patchstack.com/database/vulnerability/fg-joomla-to-wordpress/wordpress-fg-joomla-to-wordpress-plugin-4-15-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve vdb-entry
Source
cvelistV5-main/cves/2024/24xxx/CVE-2024-24837.json