PT-2024-25407 · Toast Plugins · Toast Plugins Sticky Anything

·

CVE-2024-33646

·

Published

2024-04-28

·

Updated

2024-04-30

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Toast Plugins Sticky Anything versions through 2.1.5
Description A Cross-Site Request Forgery (CSRF) issue in Toast Plugins Sticky Anything allows Cross-Site Scripting (XSS).
Recommendations For versions through 2.1.5, update to a version later than 2.1.5 to resolve the issue. As a temporary workaround, consider restricting access to sensitive functionality to minimize the risk of exploitation.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-33646

Affected Products

Toast Plugins Sticky Anything