CVE-2024-43350: WordPress Propovoice CRM plugin <= 1.7.6.4 - Insecure Direct Object References (IDOR) vulnerability
Published Aug 18, 2024
·Updated
Authorization Bypass Through User-Controlled Key vulnerability in Propovoice Propovoice CRM.This issue affects Propovoice CRM: from n/a through 1.7.6.4.
Affected Software
2 affected components
Propovoice Propovoice CRM>=n/a, <=1.7.6.4
WordPress Propovoice CRM plugin<=1.7.6.4
Event History
Aug 18, 2024
CVE Published
via MITRE·09:28 PM
Data Sourced
via MITRE·09:28 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-43350?
CVE-2024-43350 has a high severity rating due to its potential for unauthorized access to sensitive data.
2
How do I fix CVE-2024-43350?
To fix CVE-2024-43350, update Propovoice CRM to version 1.7.6.5 or later to mitigate the authorization bypass vulnerability.
3
What are the affected versions of Propovoice CRM for CVE-2024-43350?
CVE-2024-43350 affects Propovoice CRM versions from n/a up to and including 1.7.6.4.
4
Does CVE-2024-43350 affect any WordPress plugins?
Yes, CVE-2024-43350 affects the Propovoice CRM plugin for WordPress up to version 1.7.6.4.
5
What type of vulnerability is CVE-2024-43350?
CVE-2024-43350 is classified as an Authorization Bypass Through User-Controlled Key vulnerability.