PT-2024-34307 · Unknown · Fluent Forms
Kun_19
+1
·
Published
2024-09-01
·
Updated
2024-10-04
·
CVE-2024-5053
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Fluent Forms versions up to, and including, 5.1.18
Description:
The issue is related to an insufficient capability check on the
verifyRequest function, allowing Form Managers with a Subscriber-level access and above to modify the Mailchimp API key used for integration. Additionally, missing Mailchimp API key validation enables the redirect of integration requests to an attacker-controlled server.Recommendations:
For versions up to, and including, 5.1.18, update to the latest version of Fluent Forms to mitigate the risk of exploitation. As a temporary workaround, consider restricting access to the Mailchimp API key integration to prevent unauthorized modifications.
Fix
Improper Authorization
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fluent Forms