PT-2024-30452 · Sendinblue · Brevo Newsletter

Rafie Muhammad

·

Published

2024-08-26

·

Updated

2024-09-12

·

CVE-2024-43287

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Brevo Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue versions 3.1.82 and earlier
Description A Cross-Site Request Forgery (CSRF) issue affects the Brevo Newsletter, SMTP, Email marketing, and Subscribe forms by Sendinblue. This allows for potential exploitation.
Recommendations For versions 3.1.82 and earlier, upgrade to version 3.1.83 to remediate the issue. As a temporary workaround, consider restricting access to sensitive features in the affected plugin until the upgrade is applied.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-43287

Affected Products

Brevo Newsletter