First published: Mon Dec 09 2024(Updated: )
Missing Authorization vulnerability in AlexaCRM Dynamics 365 Integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dynamics 365 Integration: from n/a through 1.3.13.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Dynamics 365 Integration | <=1.3.13 | |
WordPress Dynamics 365 Integration plugin | <=1.3.13 |
Update the WordPress Dynamics 365 Integration plugin to the latest available version (at least 1.3.14).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-29422 is classified as a missing authorization vulnerability that could lead to unauthorized access.
To fix CVE-2023-29422, you should update Microsoft Dynamics 365 Integration or WordPress Dynamics 365 Integration to version 1.3.14 or later.
CVE-2023-29422 affects Microsoft Dynamics 365 Integration and WordPress Dynamics 365 Integration versions up to 1.3.13.
If exploited, CVE-2023-29422 can allow attackers to manipulate data and gain unauthorized access to sensitive information.
Yes, CVE-2023-29422 can be exploited remotely by attackers if they take advantage of incorrectly configured access control settings.