CVE-2024-37205: WordPress affiliate-toolkit plugin <= 3.4.4 - Sensitive Data Exposure via Log File vulnerability
Published Jul 10, 2024
·Updated
Insertion of Sensitive Information into Log File vulnerability in SERVIT Software Solutions.This issue affects affiliate-toolkit: from n/a through 3.4.4.
Affected Software
2 affected components
SERVIT Software Solutions affiliate-toolkit<=3.4.4
WordPress affiliate-toolkit<=3.4.4
Remediation
Information
Update to 3.4.5 or a higher version.
Event History
Jul 10, 2024
CVE Published
via MITRE·05:50 PM
Data Sourced
via MITRE·05:50 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-37205?
CVE-2024-37205 has been categorized as a medium severity vulnerability due to the exposure of sensitive information in log files.
2
How do I fix CVE-2024-37205?
To fix CVE-2024-37205, upgrade to affiliate-toolkit version 3.4.5 or higher to mitigate the vulnerability.
3
What is the impact of CVE-2024-37205?
The impact of CVE-2024-37205 includes unauthorized access to sensitive information logged by the affiliate-toolkit software.
4
Which versions are affected by CVE-2024-37205?
CVE-2024-37205 affects all versions of the affiliate-toolkit from n/a up to and including 3.4.4.
5
Who is affected by CVE-2024-37205?
Users of the affiliate-toolkit software from SERVIT Software Solutions or WordPress using affected versions are at risk from CVE-2024-37205.