CVE-2023-44240
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Oct 9, 2023
Updated: Oct 12, 2023
CWE ID 352
Summary
CVE-2023-44240 is a Cross-Site Request Forgery (CSRF) vulnerability affecting versions 1.54 and below of the Peter Butler Timthumb Vulnerability Scanner plugin. This issue allows an attacker to manipulate a user's web session, potentially leading to unauthorized actions such as data modification or account takeover. The CSRF vulnerability occurs due to insufficient input validation and authorization checks, making it crucial for users to update their plugin as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.