Cross-Site Request Forgery Vulnerability in Smartsupp Live Chat by Smartsupp
CVE-2024-38790

6.5MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
2 January 2025

Summary

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in Smartsupp's live chat, chatbots, AI, and lead generation platform. This security flaw allows an attacker to trick users into executing unwanted actions on behalf of the authenticated user without their consent. The vulnerability poses a risk to users from the initial release of the product through version 3.6. It is crucial for users running affected versions to take appropriate measures to mitigate potential exploitation of this vulnerability.

Affected Version(s)

Smartsupp – live chat, chatbots, AI and lead generation <= 3.6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack)
.