First published: Mon Dec 09 2024(Updated: )
Missing Authorization vulnerability in RedNao Smart Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Forms: from n/a through 2.6.84.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Baal Smart Forms | >n/a<=2.6.84 | |
WordPress Smart Forms plugin | <=2.6.84 |
No patched version is available.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-49856 is classified as a critical vulnerability due to its potential to exploit incorrectly configured access controls.
To fix CVE-2023-49856, ensure that access control security levels are correctly configured in RedNao Smart Forms and upgrade to the latest version beyond 2.6.84.
CVE-2023-49856 affects RedNao Smart Forms from an unspecified version up to and including version 2.6.84.
Yes, CVE-2023-49856 can potentially be exploited remotely due to the missing authorization issues.
Users of RedNao Smart Forms and the WordPress Smart Forms plugin up to version 2.6.84 are at risk of CVE-2023-49856.