CVE-2023-25989 Vulnerability Details
/
/
/
CVE-2023-25989 Metadata Quick Info
CVE Published: 03/10/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023
Source: Patchstack |
Vendor: Meks |
Product: Meks Video Importer
Status : PUBLISHED
CVE-2023-25989 Description
Cross-Site Request Forgery (CSRF) vulnerability in Meks Video Importer, Meks Time Ago, Meks ThemeForest Smart Widget, Meks Smart Author Widget, Meks Audio Player, Meks Easy Maps, Meks Easy Photo Feed Widget, Meks Simple Flickr Widget, Meks Easy Ads Widget, Meks Smart Social Widget plugins leading to dismiss or the popup.
Metrics
CVSS Version: 3.1 |
Base Score: 4.3 MEDIUM
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
l➤ Exploitability Metrics:
Attack Vector (AV)* NETWORK
Attack Complexity (AC)* LOW
Privileges Required (PR)* NONE
User Interaction (UI)* REQUIRED
Scope (S)* UNCHANGED
l➤ Impact Metrics:
Confidentiality Impact (C)* NONE
Integrity Impact (I)* LOW
Availability Impact (A)* NONE
Weakness Enumeration (CWE)
CWE-ID: CWE-352
CWE Name: CWE-352 Cross-Site Request Forgery (CSRF)
Source: Meks
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID: CAPEC-62
CAPEC Description: CAPEC-62 Cross Site Request Forgery
Source: NVD (National Vulnerability Database).