CVE-2023-45268
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Oct 13, 2023
Updated: Oct 18, 2023
CWE ID 352
Summary
CVE-2023-45268 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Hitsteps Hitsteps Web Analytics plugin versions 5.86 and below. This issue allows an attacker to force unintended actions from a user's web browser, potentially resulting in data theft or unauthorized changes. The attacker can craft a malicious request and trick the user into visiting a specially crafted webpage, leading to the execution of the attack. Users of the Hitsteps plugin are advised to update to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share