First published: Tue Dec 19 2023(Updated: )
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Integration for WooCommerce and QuickBooks.This issue affects Integration for WooCommerce and QuickBooks: from n/a through 1.2.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Crmperks Integration For Woocommerce And Quickbooks | <=1.2.3 |
Update to 1.2.4 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-38478 is classified as critical due to its potential for open redirection to untrusted sites.
To fix CVE-2023-38478, update the Integration for WooCommerce and QuickBooks plugin to a version later than 1.2.3.
CVE-2023-38478 affects the Integration for WooCommerce and QuickBooks plugin for WordPress versions up to 1.2.3.
Yes, CVE-2023-38478 can be exploited to redirect users to untrusted external sites.
As of now, the best workaround for CVE-2023-38478 is to disable the plugin until it is updated.