PT-2024-12166 · Codepeople · Codepeople Cp Multi View Event Calendar

István Márton

·

Published

2024-06-03

·

Updated

2024-07-18

·

CVE-2023-28492

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions CodePeople CP Multi View Event Calendar versions 1.4.10 and earlier
Description The issue is related to a Missing Authorization vulnerability, allowing functionality misuse in the CodePeople CP Multi View Event Calendar.
Recommendations For versions 1.4.10 and earlier, update to a version later than 1.4.10 to resolve the issue. At the moment, there is no information about additional mitigation measures.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

BIT-WORDPRESS-2023-28492
BIT-WORDPRESS-MULTISITE-2023-28492
CVE-2023-28492

Affected Products

Codepeople Cp Multi View Event Calendar