CVE-2023-3025
Published on: Not Yet Published
Last Modified on: 09/20/2023 01:24:00 PM UTC
Certain versions of Dropbox Folder Share from Hynotech contain the following vulnerability:
The Dropbox Folder Share plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.9.7 via the 'link' parameter. This can allow unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
- CVE-2023-3025 has been assigned by
securit[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
hyno - Dropbox Folder Share version <= 1.9.7
CVSS3 Score: 7.2 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
CHANGED | LOW | LOW | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Dropbox Folder Share <= 1.9.7 - Unauthenticated Server-Side Request Forgery via 'link' | www.wordfence.com text/html |
![]() |
403 Forbidden | plugins.trac.wordpress.org text/html Inactive LinkNot Archived |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Hynotech | Dropbox Folder Share | All | All | All | All |
- cpe:2.3:a:hynotech:dropbox_folder_share:*:*:*:*:*:wordpress:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|