Denial of Service Vulnerability in Craft CMS Feed Me Plugin
CVE-2023-36260
7.5HIGH
Summary
A vulnerability in the Feed Me plugin version 4.6.1 for Craft CMS allows remote attackers to trigger a denial of service (DoS) condition. This situation arises from the improper handling of crafted strings directed at the Feed-Me Name and Feed-Me URL fields, specifically when using an Asset element type without selecting a volume. While the vulnerability is related to the plugin itself, it remains essential to note that related commits do not address security concerns. Administrators using this plugin should assess their configurations to mitigate potential exploits.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved