First published: Mon Dec 09 2024(Updated: )
Missing Authorization vulnerability in AlexaCRM Dynamics 365 Integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dynamics 365 Integration: from n/a through 1.3.12.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Dynamics 365 | <=1.3.12 | |
WordPress Dynamics 365 Integration plugin | <=1.3.12 |
Update the WordPress Dynamics 365 Integration plugin to the latest available version (at least 1.3.13).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-28417 has been classified with a medium severity due to its missing authorization vulnerability.
To fix CVE-2023-28417, ensure that access control security levels are correctly configured in your applications.
CVE-2023-28417 affects all versions of the AlexaCRM Dynamics 365 Integration up to and including 1.3.12.
CVE-2023-28417 is a missing authorization vulnerability that allows exploitation of incorrectly configured access controls.
CVE-2023-28417 impacts the AlexaCRM Dynamics 365 Integration and WordPress Dynamics 365 Integration products up to version 1.3.12.