CVE-2024-7817: Misiek Photo Album <= 1.4.3 - Album Deletion via CSRF
Published Sep 12, 2024
·Updated
The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF checks in some places, which could allow attackers to make logged in users delete arbitrary albums via a CSRF attack
Affected Software
1 affected component
Michalaugustyniak Misiek Photo Album Wordpress<=1.4.3
Event History
Sep 12, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Jul 4, 56726
Event
via FIRST·01:15 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-7817?
CVE-2024-7817 has a high severity rating due to the potential for attackers to perform CSRF attacks that could delete arbitrary user albums.
2
How do I fix CVE-2024-7817?
To fix CVE-2024-7817, update the Misiek Photo Album plugin to the latest version that includes CSRF protection.
3
What specific vulnerability does CVE-2024-7817 exploit?
CVE-2024-7817 exploits the lack of CSRF checks in the Misiek Photo Album WordPress plugin.
4
Who is impacted by CVE-2024-7817?
Users of the Misiek Photo Album WordPress plugin version 1.4.3 and earlier are impacted by CVE-2024-7817.
5
What kind of attacks can be performed using CVE-2024-7817?
CVE-2024-7817 allows attackers to execute CSRF attacks that can lead to unauthorized deletion of photo albums.