CVE-2023-47652
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Nov 13, 2023
Updated: Nov 16, 2023
CWE ID 352
Summary
CVE-2023-47652 is a Cross-Site Request Forgery (CSRF) vulnerability identified in Lucian Apostol Auto Affiliate Links. This issue allows Stored XSS attacks, enabling an attacker to inject malicious code into a user's browser and potentially steal sensitive information or perform unintended actions. The vulnerability affects Auto Affiliate Links versions from n/a through 6.4.2.4. Users are advised to update their software to the latest version or implement appropriate security measures to mitigate the risk of this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share