CVE-2023-47779
Last modified
CVE-2023-47779 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks. Integration for Constant Contact and Contact Form 7, WPForms, Elementor, Ninja Forms.This issue affects Integration for Constant Contact and Contact Form 7, WPForms, Elementor, Ninja Forms: from n/a through 1.1.4.. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks. Integration for Constant Contact and Contact Form 7, WPForms, Elementor, Ninja Forms.This issue affects Integration for Constant Contact and Contact Form 7, WPForms, Elementor, Ninja Forms: from n/a through 1.1.4.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Crmperks | Integration For Constant Contact And Contact Form 7\, Wpforms\, Elementor\, Ninja | < 1.1.5 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-47779?
How severe is CVE-2023-47779?
How do I fix CVE-2023-47779?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-47773Improper Neutralization of Input During Web Page Generation …6.1
- CVE-2023-47774Improper Restriction of Rendered UI Layers or Frames vulnera…5.4
- CVE-2023-47775Cross-Site Request Forgery (CSRF) vulnerability in gVectors …8.8
- CVE-2023-47776Missing Authorization vulnerability in miniOrange miniorange…4.3
- CVE-2023-47777Improper Neutralization of Input During Web Page Generation …5.4
- CVE-2023-47778Missing Authorization vulnerability in LuckyWP LuckyWP Scrip…4.3
- CVE-2023-4778Out-of-bounds Read in GitHub repository gpac/gpac prior to 2…5.5
- CVE-2023-47780Missing Authorization vulnerability in flowdee EasyAzon easy…4.3
- CVE-2023-47781Cross-Site Request Forgery (CSRF) vulnerability in Thrive Th…8.8
- CVE-2023-47782Improper Privilege Management vulnerability in Thrive Themes…8.8
- CVE-2023-47783Missing Authorization vulnerability in Thrive Themes Thrive …8.3
- CVE-2023-47784Unrestricted Upload of File with Dangerous Type vulnerabilit…8.8
Are you affected by CVE-2023-47779?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
