Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) Vulnerability in MyBookTable Bookstore
CVE-2024-43255

6.1MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
26 August 2024

Summary

A security vulnerability exists in Stormhill Media's MyBookTable Bookstore, which is susceptible to Cross-Site Request Forgery (CSRF) that can lead to Cross-Site Scripting (XSS) attacks. This issue compromises the integrity of user inputs, allowing attackers to execute malicious scripts in the context of the affected application. The versions ranging from n/a up to 3.3.9 are impacted, making it essential for users to apply necessary security patches to mitigate risks.

Affected Version(s)

MyBookTable Bookstore <= 3.3.9

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

Credit

Majed Refaea (Patchstack Alliance)
.