CVE-2023-34387
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Dec 13, 2024
CWE ID 862
Summary
CVE-2023-34387 is a Missing Authorization vulnerability affecting Constant Contact Forms from an unknown version up to 2.0.3. This issue arises due to incorrectly configured access control security levels, enabling attackers to exploit the vulnerability. As a result, unauthorized users may gain access to sensitive information or perform unintended actions, leading to potential data breaches or system compromises. Constant Contact urges users to update their forms to the latest version and implement strong access control measures to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share