PT-2023-19447 · Vcita · Online Booking & Scheduling Calendar For Wordpress

·

CVE-2023-2416

·

Publicado

2023-06-03

·

Atualizado

2025-06-10

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress versions up to, and including, 4.2.10
Description The issue is related to a missing nonce check on the vcita logout callback function, which makes it possible for unauthenticated attackers to logout a vcita connected account. This can cause a denial of service on the appointment scheduler via a forged request, granted they can trick a site user into performing an action such as clicking on a link.
Recommendations For versions up to, and including, 4.2.10, update to a version that includes a fix for the missing nonce check on the vcita logout callback function to prevent Cross-Site Request Forgery attacks. As a temporary workaround, consider restricting access to the vcita logout callback function until a patch is available.

Exploit

Correção

DoS

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-2416

Produtos afetados

Online Booking & Scheduling Calendar For Wordpress