PT-2024-13814 · Klbtheme · Klbtheme Bacola+6
Fearzzzz
+2
·
Published
2024-03-26
·
Updated
2024-03-26
·
CVE-2023-49838
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
KlbTheme Clotya theme versions 1.1.6 and earlier
KlbTheme Cosmetsy theme versions 1.7.7 and earlier
KlbTheme Furnob theme versions 1.2.2 and earlier
KlbTheme Bacola theme versions 1.3.3 and earlier
KlbTheme Partdo theme versions 1.1.1 and earlier
KlbTheme Medibazar theme versions 1.8.6 and earlier
KlbTheme Machic theme versions 1.2.8 and earlier
Description
A Cross-Site Request Forgery (CSRF) issue affects several KlbTheme products. This issue allows for malicious requests to be made on behalf of the user without their knowledge or consent.
Recommendations
For KlbTheme Clotya theme versions 1.1.6 and earlier, update to a version that includes a fix for this issue.
For KlbTheme Cosmetsy theme versions 1.7.7 and earlier, update to a version that includes a fix for this issue.
For KlbTheme Furnob theme versions 1.2.2 and earlier, update to a version that includes a fix for this issue.
For KlbTheme Bacola theme versions 1.3.3 and earlier, update to a version that includes a fix for this issue.
For KlbTheme Partdo theme versions 1.1.1 and earlier, update to a version that includes a fix for this issue.
For KlbTheme Medibazar theme versions 1.8.6 and earlier, update to a version that includes a fix for this issue.
For KlbTheme Machic theme versions 1.2.8 and earlier, update to a version that includes a fix for this issue.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Klbtheme Bacola
Klbtheme Clotya
Klbtheme Cosmetsy
Klbtheme Furnob
Klbtheme Machic
Klbtheme Medibazar
Klbtheme Partdo