Cross-Site Request Forgery Vulnerability in The Events Calendar Event Tickets by Modern Tribe
CVE-2024-38762
4.3MEDIUM
Summary
The vulnerability enables attackers to initiate unauthorized requests on behalf of users without their consent, leveraging the Event Tickets plugin within The Events Calendar ecosystem. This Cross-Site Request Forgery (CSRF) issue affects all versions of Event Tickets up to and including 5.11.0.4, exposing users to potential transactional exploits and unauthorized actions. It is crucial for users to apply security measures and updates to mitigate the risks associated with this vulnerability.
Affected Version(s)
Event Tickets <= 5.11.0.4
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Joshua Chan (Patchstack Alliance)