PT-2023-30611 · Popoon · Pz-Linkcard Plugin

Le Ngoc Anh

·

Published

2023-11-22

·

Updated

2023-11-28

·

CVE-2023-47790

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Poporon Pz-LinkCard plugin versions prior to 2.4.9
Description The issue is related to a Cross-Site Request Forgery (CSRF) that can lead to Cross-Site Scripting (XSS). This means an attacker could potentially trick a user into performing unintended actions on a web application, and also inject malicious scripts into the website.
Recommendations For versions prior to 2.4.9, update to version 2.4.9 or later to resolve the issue.

Fix

CSRF

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-47790

Affected Products

Pz-Linkcard Plugin