CVE-2023-47550

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Nov 14, 2023
Updated: Nov 17, 2023
CWE ID 352

Summary

CVE-2023-47550 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the RedNao Donations Made Easy – Smart Donations plugin. This issue allows for Stored XSS attacks, enabling an attacker to inject malicious code into a user's browser. The vulnerability can be exploited by tricking a user into clicking a specially crafted link, potentially leading to data theft or unauthorized donations. This issue affects Donations Made Easy – Smart Donations versions from n/a through 4.0.12.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share