First published: Fri Jun 21 2024(Updated: )
Cross Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.7.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tribulant Newsletters | <4.9.8 |
Update to 4.9.8 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37227 has been assigned a medium severity level due to its Cross Site Request Forgery (CSRF) nature.
To fix CVE-2024-37227, upgrade the Tribulant Newsletters plugin to version 4.9.8 or later.
CVE-2024-37227 affects Tribulant Newsletters versions from n/a through 4.9.7.
CVE-2024-37227 is categorized as a Cross Site Request Forgery (CSRF) vulnerability.
Yes, CVE-2024-37227 can potentially allow unauthorized commands to be executed on behalf of authenticated users.