Calculated Fields Form Vulnerable to Functionality Misuse Due to Missing Authorization
CVE-2023-26523
4.3MEDIUM
Summary
A missing authorization vulnerability in the CodePeople Calculated Fields Form plugin creates potential for functionality misuse. This vulnerability allows unauthorized users to exploit the features of the plugin, potentially leading to unintended actions or data submission. The affected versions range from an unspecified initial version up to 1.1.120. Users of the Calculated Fields Form plugin should take appropriate measures to mitigate the risks associated with this vulnerability.
Affected Version(s)
Calculated Fields Form <= 1.1.120
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
István Márton (Patchstack Alliance)