CVE-2024-37463: WordPress CRM Perks Forms plugin <= 1.1.5 - Broken Access Control vulnerability
Published Nov 1, 2024
·Updated
Missing Authorization vulnerability in CRM Perks CRM Perks Forms allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects CRM Perks Forms: from n/a through 1.1.5.
Affected Software
3 affected components
crmperks Crm Perks Forms Wordpress<1.1.6
CRM Perks CRM Perks Forms<=1.1.5
WordPress CRM Perks Forms<=1.1.5
Remediation
Information
Update to 1.1.6 or a higher version.
Event History
Nov 1, 2024
CVE Published
via MITRE·02:18 PM
Data Sourced
via MITRE·02:18 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Feb 22, 57075
Event
via NVD·07:32 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-37463?
CVE-2024-37463 is considered a moderate severity vulnerability due to its missing authorization controls.
2
How do I fix CVE-2024-37463?
To fix CVE-2024-37463, update the CRM Perks Forms plugin to version 1.1.6 or later.
3
What functionality is affected by CVE-2024-37463?
CVE-2024-37463 allows unauthorized access to certain functionalities not properly constrained by Access Control Lists (ACLs).
4
Who is affected by CVE-2024-37463?
CVE-2024-37463 affects all users of CRM Perks Forms versions from n/a through 1.1.5.
5
What can attackers do with CVE-2024-37463?
Attackers exploiting CVE-2024-37463 can gain access to features and data they are not authorized to access.