Record summary

CVE-2023-23897 has a selected CVSS score of 4.3 (medium); EIP currently links 1 Nuclei template.

Description

Cross-Site Request Forgery (CSRF) vulnerability in Ozette Plugins Simple Mobile URL Redirect plugin <= 1.7.2 versions.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Oct 30, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 2, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListThrough 1.7.2affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMOzette Plugins - Cross-Site Request ForgeryCVSS 4.3

An attacker can update, create, and remove the site's mobile redirects via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Impact

Attackers can perform unauthorized actions on behalf of authenticated users, potentially leading to data manipulation or unauthorized redirects.

Remediation

Update to version 1.7.3 or later with CSRF protections implemented.

WeaknessesCWE-352
Authorspopcorn94
Template tagscvecve2023wordpresswppluginsozettecsrfvulnauthenticatedvkevsimple-mobile-url-redirect
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CPE: cpe:2.3:a:ozette:simple_mobile_url_redirect:*:*:*:*:*:wordpress:*:*
Shodan: html:"simple-mobile-url-redirect"

Source: ProjectDiscovery

References

2