PT-2024-11911 · Freemius · Freemius Sdk

James Marsland

+2

·

Published

2024-10-15

·

Updated

2024-10-16

·

CVE-2022-4974

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Freemius SDK versions up to, and including 2.4.2 Freemius SDK versions prior to 2.4.3
Description The issue concerns Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the checkPassword() is not mentioned but the following functions are: get debug log, get db option, and the set db option functions.
Recommendations For Freemius SDK versions up to, and including 2.4.2, update to version 2.4.3 or later. For Freemius SDK versions prior to 2.4.3, update to version 2.4.3 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-4974

Affected Products

Freemius Sdk