First published: Wed Jan 31 2024(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder Pro.This issue affects Profile Builder Pro: from n/a through 3.10.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cozmoslabs Profile Builder | <=3.10.0 |
Update to 3.10.1 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22140 is classified as a high severity Cross-Site Request Forgery (CSRF) vulnerability.
To fix CVE-2024-22140, update the Cozmoslabs Profile Builder Pro plugin to version 3.10.1 or higher.
CVE-2024-22140 affects Profile Builder Pro versions up to and including 3.10.0.
CVE-2024-22140 is a Cross-Site Request Forgery (CSRF) vulnerability.
Yes, CVE-2024-22140 can potentially lead to account takeover due to its CSRF nature.