First published: Mon Apr 15 2024(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in IP2Location Download IP2Location Country Blocker.This issue affects Download IP2Location Country Blocker: from n/a through 2.34.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
IP2Location Country Blocker | <=2.34.2 | |
IP2Location Country Blocker | <=2.34.2 | |
IP2Location Country Blocker | <2.34.3 |
Update to 2.34.3 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-32443 is classified as a Cross-Site Request Forgery (CSRF) vulnerability, which can allow an attacker to perform unauthorized actions on behalf of a user.
CVE-2024-32443 affects versions of IP2Location Download IP2Location Country Blocker up to and including 2.34.2.
To fix CVE-2024-32443, upgrade to a version of IP2Location Download IP2Location Country Blocker that is higher than 2.34.2.
Yes, CVE-2024-32443 can impact user sessions by potentially allowing attackers to hijack sessions through forged requests.
CVE-2024-32443 is specific to the IP2Location Country Blocker plugin, which is available for both IP2Location and WordPress platforms.