First published: Thu Nov 30 2023(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force US LLC CartFlows Pro allows Cross Site Request Forgery.This issue affects CartFlows Pro: from n/a through 1.11.12.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
CartFlows | <=1.11.12 |
Update to 1.11.13 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-36685 is high with a severity value of 8.8.
CVE-2023-36685 allows for Cross-Site Request Forgery (CSRF) attacks in the CartFlows Pro plugin.
CartFlows Pro versions up to and including 1.11.12 are affected by CVE-2023-36685.
Cross-Site Request Forgery (CSRF) is an attack that tricks the victim into submitting a malicious request, causing undesired actions to be performed on their behalf.
Yes, a fix is available for CVE-2023-36685. Details can be found at the provided reference link.