CVE-2024-49672

Cross-Site Request Forgery (CSRF) vulnerability in Gifford Cheung, Brian Watanabe, Chongsun Ahn Google Docs RSVP allows Stored XSS.This issue affects Google Docs RSVP: from n/a through 2.0.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:google_docs_rsvp_project:google_docs_rsvp:*:*:*:*:*:wordpress:*:*

History

08 Nov 2024, 15:16

Type Values Removed Values Added
References () https://patchstack.com/database/vulnerability/google-docs-rsvp-guestlist/wordpress-google-docs-rsvp-plugin-2-0-1-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve - () https://patchstack.com/database/vulnerability/google-docs-rsvp-guestlist/wordpress-google-docs-rsvp-plugin-2-0-1-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve - Third Party Advisory
CPE cpe:2.3:a:google_docs_rsvp_project:google_docs_rsvp:*:*:*:*:*:wordpress:*:*
CVSS v2 : unknown
v3 : 7.1
v2 : unknown
v3 : 6.1
First Time Google Docs Rsvp Project
Google Docs Rsvp Project google Docs Rsvp

29 Oct 2024, 14:34

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de falsificación de solicitud entre sitios (CSRF) en Google Docs RSVP de Gifford Cheung, Brian Watanabe y Chongsun Ahn permite XSS almacenado. Este problema afecta a Google Docs RSVP: desde n/a hasta 2.0.1.

29 Oct 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-29 11:15

Updated : 2024-11-08 15:16


NVD link : CVE-2024-49672

Mitre link : CVE-2024-49672

CVE.ORG link : CVE-2024-49672


JSON object : View

Products Affected

google_docs_rsvp_project

  • google_docs_rsvp
CWE
CWE-352

Cross-Site Request Forgery (CSRF)