Fusion Builder CSRF Vulnerability Affects Versions n/a through 3.11.1
CVE-2023-39311
7.1HIGH
Summary
A Cross-Site Request Forgery (CSRF) vulnerability exists in the ThemeFusion Fusion Builder, impacting versions from an unspecified point up to and including 3.11.1. This security flaw allows an attacker to trick a user into executing unwanted actions on a web application in which they are authenticated. If exploited, the vulnerability could lead to unauthorized access or data manipulation, posing significant security risks to both the application and its users. Proper validation and implementation of CSRF tokens are essential for mitigating this flaw.
Affected Version(s)
Fusion Builder <= 3.11.1
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Rafie Muhammad (Patchstack)