PT-2022-26024 · Woocommerce · Viszt Péter'S Integration For Szamlazz.Hu & Woocommerce+1

István Márton

+1

·

Published

2022-11-18

·

Updated

2022-11-23

·

CVE-2022-41685

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Viszt Péter's Integration for Szamlazz.hu & WooCommerce plugin versions <= 5.6.3.2 Csomagpontok és szállítási címkék WooCommerce-hez plugin versions <= 1.9.0.2
Description The issue concerns multiple Cross-Site Request Forgery (CSRF) vulnerabilities. CSRF is a type of attack where an attacker tricks a user into performing unintended actions on a web application that the user is authenticated to. This can happen when a user is logged into a website and an attacker tricks them into clicking a link or submitting a form that performs an action on the website without the user's knowledge.
Recommendations For Viszt Péter's Integration for Szamlazz.hu & WooCommerce plugin versions <= 5.6.3.2, update to a version higher than 5.6.3.2. For Csomagpontok és szállítási címkék WooCommerce-hez plugin versions <= 1.9.0.2, update to a version higher than 1.9.0.2.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2022-41685

Affected Products

Csomagpontok És Szállítási Címkék Woocommerce-Hez
Viszt Péter'S Integration For Szamlazz.Hu & Woocommerce