Permalink
CVE-2024-38766
4.3 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): REQUIRED
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): LOW
- Availability impact (A): NONE
WordPress Matomo Analytics plugin <= 5.1.1 - Cross Site Request Forgery (CSRF) leading to Notice Dismissal vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Matomo Matomo Analytics allows Cross Site Request Forgery.This issue affects Matomo Analytics: from n/a through 5.1.1.
References
Affected products
matomo
- =<5.1.1
Package maintainers
-
@Twey James ‘Twey’ Kay <twey@twey.co.uk>
-
@frlan Frank Lanitz <frank@frank.uvena.de>
-
@leona-ya Leona Maroni <nix@leona.is>
-
@dpausp Tobias Stenzel <dpausp@posteo.de>
-
@niklaskorz Niklas Korz <nixpkgs@korz.dev>
-
@sebbel Sebastian Ball <hej@sebastian-ball.de>
-
@florianjacob Florian Jacob <projects+nixos@florianjacob.de>
-
@boozedog David A. Buser <code@booze.dog>
-
@osnyx Oliver Schmidt <os@flyingcircus.io>
-
@ctheune Christian Theune <ct@flyingcircus.io>