First published: Fri Dec 13 2024(Updated: )
Missing Authorization vulnerability in Gesundheit Bewegt GmbH Zippy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zippy: from n/a through 1.6.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Zippy | <=1.6.2 | |
WordPress Zippy plugin | <=1.6.2 |
Update the WordPress Zippy plugin to the latest available version (at least 1.6.3).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-34381 is classified as a critical vulnerability due to its potential for unauthorized access and data exposure.
To resolve CVE-2023-34381, users should upgrade Zippy to version 1.6.3 or later to ensure proper access control settings.
CVE-2023-34381 affects all versions of Zippy up to and including 1.6.2.
CVE-2023-34381 is categorized as a Missing Authorization vulnerability, leading to potential exploitation through incorrectly configured access controls.
CVE-2023-34381 is associated with Gesundheit Bewegt GmbH as the vendor of the Zippy product.