Mailchimp Easy Forms Vulnerable to Missing Authorization
CVE-2024-35742
7.3HIGH
Summary
A Missing Authorization vulnerability exists in Code Parrots Easy Forms for Mailchimp, impacting versions from n/a to 6.9.0. This vulnerability allows unauthorized users to gain access to certain functionalities, potentially leading to unauthorized data exposure and manipulation. Proper access controls should be implemented to safeguard sensitive operations and user data within the application. Affected users should promptly update to the latest version to mitigate risks associated with this vulnerability.
Affected Version(s)
Easy Forms for Mailchimp <= 6.9.0
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
NGÔ THIÊN AN / ancorn_ from VNPT-VCI (Patchstack Alliance)