QID 996585
Date Published: 2024-01-11
QID 996585: PHP (Composer) Security Update for woocommerce/woocommerce (GHSA-rcmf-88p4-9wrg)
WooCommerce before 3.6.5, when it handles CSV imports of products, has a cross-site request forgery (CSRF) issue with resultant stored cross-site scripting (XSS) via includes/admin/importers/class-wc-product-csv-importer-controller.php.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-rcmf-88p4-9wrg for updates and patch information.
Vendor References
- GHSA-rcmf-88p4-9wrg -
github.com/advisories/GHSA-rcmf-88p4-9wrg
CVEs related to QID 996585
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-rcmf-88p4-9wrg | woocommerce/woocommerce |
|