First published: Wed May 03 2023(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Pods Framework Team Pods – Custom Content Types and Fields plugin <= 2.9.10.2 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pods Foundation | <2.9.11 |
Update to 2.9.11 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-23790 is considered medium due to its potential to enable unauthorized actions on behalf of authenticated users.
To fix CVE-2023-23790, update the Pods Framework Team Pods – Custom Content Types and Fields plugin to version 2.9.11 or higher.
The impact of CVE-2023-23790 could include unauthorized actions performed on behalf of users, potentially leading to data manipulation or user account compromise.
CVE-2023-23790 affects versions of the Pods – Custom Content Types and Fields plugin up to and including 2.9.10.2.
There is no official workaround for CVE-2023-23790; the best practice is to update to the latest version to mitigate the risk.