PT-2024-30468 · Unknown · Fonts Plugin Fonts

Rafie Muhammad

·

Published

2024-08-26

·

Updated

2024-09-12

·

CVE-2024-43301

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Fonts Plugin Fonts versions n/a through 3.7.7
Description The issue is a Cross-Site Request Forgery (CSRF) vulnerability in the Fonts Plugin Fonts, which allows Stored XSS. This means an attacker can trick a user into performing unintended actions on the web application, potentially leading to the execution of malicious scripts.
Recommendations For versions n/a through 3.7.7, upgrade to version 3.7.8 to remediate the issue. As a temporary workaround, consider restricting access to the Fonts Plugin until the upgrade is applied.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-43301

Affected Products

Fonts Plugin Fonts