PT-2022-26024 · Woocommerce · Viszt Péter'S Integration For Szamlazz.Hu & Woocommerce+1
István Márton
+1
·
Published
2022-11-18
·
Updated
2022-11-23
·
CVE-2022-41685
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Viszt Péter's Integration for Szamlazz.hu & WooCommerce plugin versions <= 5.6.3.2
Csomagpontok és szállítási címkék WooCommerce-hez plugin versions <= 1.9.0.2
Description
The issue concerns multiple Cross-Site Request Forgery (CSRF) vulnerabilities. CSRF is a type of attack where an attacker tricks a user into performing unintended actions on a web application that the user is authenticated to. This can happen when a user is logged into a website and an attacker tricks them into clicking a link or submitting a form that performs an action on the website without the user's knowledge.
Recommendations
For Viszt Péter's Integration for Szamlazz.hu & WooCommerce plugin versions <= 5.6.3.2, update to a version higher than 5.6.3.2.
For Csomagpontok és szállítási címkék WooCommerce-hez plugin versions <= 1.9.0.2, update to a version higher than 1.9.0.2.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Csomagpontok És Szállítási Címkék Woocommerce-Hez
Viszt Péter'S Integration For Szamlazz.Hu & Woocommerce