Google Drive Vulnerable to Data Modification and Loss Due to Missing Capability Check
CVE-2024-2086
10CRITICAL
What is CVE-2024-2086?
The Integrate Google Drive plugin for WordPress is susceptible to security weaknesses resulting from a lack of proper capability checks on several AJAX endpoints. This vulnerability affects all versions up to and including 1.3.8, allowing authenticated attackers to gain unauthorized access to sensitive data and modify plugin configurations. Furthermore, the flaw enables full read, write, and delete capabilities on Google Drive files associated with the plugin, posing significant risks to data integrity and confidentiality.
Affected Version(s)
File Manager for Google Drive โ Integrate Google Drive 0 <= 1.3.8
References
CVSS V3.1
Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
Krzysztof Zajฤ
c