Google Docs RSVP Cross-Site Request Forgery Vulnerability Allows Stored XSS
CVE-2024-49672
7.1HIGH
What is CVE-2024-49672?
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Google Docs RSVP plugin developed by Gifford Cheung. This flaw allows attackers to execute unauthorized actions on behalf of users, potentially leading to stored Cross-Site Scripting (XSS) attacks. The issue affects versions of the plugin up to and including 2.0.1, making it critical for users to update to the latest version to safeguard against potential exploits.
Affected Version(s)
Google Docs RSVP 0 <= 2.0.1