Assigner | Patchstack |
Reserved | 2024-03-27 |
Published | 2024-06-09 |
Updated | 2024-07-17 |
Description
Missing Authorization vulnerability in XLPlugins Finale Lite.This issue affects Finale Lite: from n/a through 2.18.0.
HIGH: 8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Problem types
CWE-862 Missing Authorization
Product status
Default status
unaffected
Any version
affected
Credits
Yudistira Arya (Patchstack Alliance) finder
References
https://patchstack.com/database/vulnerability/finale-woocommerce-sales-countdown-timer-discount/wordpress-finale-lite-plugin-2-18-0-subscriber-arbitrary-plugin-installation-activation-vulnerability?_s_id=cve vdb-entry
cve.org CVE-2024-30485
nvd.nist.gov CVE-2024-30485
Download JSON