PT-2024-15159 · 10Web · 10Web Ai Assistant

Krzysztof Zając

·

Published

2024-02-05

·

Updated

2024-02-13

·

CVE-2023-6985

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions 10Web AI Assistant versions up to, and including, 1.0.18
Description The issue allows authenticated attackers with subscriber-level access and above to install arbitrary plugins, potentially gaining further access to a compromised site. This is due to a missing capability check on the install plugin AJAX action.
Recommendations For versions up to, and including, 1.0.18, update to a version higher than 1.0.18 to resolve the issue. As a temporary workaround, consider restricting access to the install plugin AJAX action to prevent unauthorized plugin installations.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-6985

Affected Products

10Web Ai Assistant