PT-2024-35255 · Skpstorm · Skpstorm Sk Wp Settings Backup
Mika
·
Published
2024-11-16
·
Updated
2024-11-18
·
CVE-2024-52415
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Skpstorm SK WP Settings Backup versions n/a through 1.0
Description
A Cross-Site Request Forgery (CSRF) vulnerability in Skpstorm SK WP Settings Backup allows Object Injection. This issue enables an attacker to inject objects, potentially leading to unauthorized actions on the affected system.
Recommendations
For versions n/a through 1.0, update to a version that includes a fix for this issue, as no specific workaround is provided for these versions.
As a temporary workaround, consider implementing additional security measures to prevent CSRF attacks, such as validating request origins and using anti-CSRF tokens, until a patch is available.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Skpstorm Sk Wp Settings Backup