First published: Tue Nov 19 2024(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Repute InfoSystems ARMember, Repute InfoSystems ARMember Premium allows Cross-Site Request Forgery.This issue affects ARMember: from n/a through 4.0.5; ARMember Premium: from n/a before 6.7.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Repute Infosystems ARMember Premium | >n/a<=4.0.5 | |
Repute Infosystems ARMember – Membership Plugin | >n/a<6.7.1 | |
WordPress ARMember | <=4.0.5 |
Update ARMember to 4.0.6 or a higher version.
Update ARMember Premium to 6.7.1 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-47424 is classified as a Cross-Site Request Forgery (CSRF) vulnerability that can lead to unauthorized actions on behalf of users.
To mitigate CVE-2022-47424, upgrade ARMember to version 4.0.6 or higher, and ARMember Premium to version 6.7.1 or higher.
CVE-2022-47424 affects ARMember versions n/a through 4.0.5 and ARMember Premium versions n/a before 6.7.1.
If you are running ARMember version 4.0.5 or earlier, or ARMember Premium version prior to 6.7.1, your installation is vulnerable to CVE-2022-47424.
CVE-2022-47424 can allow attackers to perform actions on behalf of an authenticated user, potentially compromising user accounts.