CVE-2023-1092

The OAuth Single Sign On Free WordPress plugin before 6.24.2, OAuth Single Sign On Standard WordPress plugin before 28.4.9, OAuth Single Sign On Premium WordPress plugin before 38.4.9 and OAuth Single Sign On Enterprise WordPress plugin before 48.4.9 do not have CSRF checks when deleting Identity Providers (IdP), which could allow attackers to make logged in admins delete arbitrary IdP via a CSRF attack
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:miniorange:oauth_single_sign_on:*:*:*:*:free:wordpress:*:*
cpe:2.3:a:miniorange:oauth_single_sign_on:*:*:*:*:standard:wordpress:*:*
cpe:2.3:a:miniorange:oauth_single_sign_on:*:*:*:*:premium:wordpress:*:*
cpe:2.3:a:miniorange:oauth_single_sign_on:*:*:*:*:enterprise:wordpress:*:*

History

07 Nov 2023, 04:02

Type Values Removed Values Added
CWE CWE-352

03 Apr 2023, 16:07

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
First Time Miniorange
Miniorange oauth Single Sign On
CPE cpe:2.3:a:miniorange:oauth_single_sign_on:*:*:*:*:premium:wordpress:*:*
cpe:2.3:a:miniorange:oauth_single_sign_on:*:*:*:*:standard:wordpress:*:*
cpe:2.3:a:miniorange:oauth_single_sign_on:*:*:*:*:free:wordpress:*:*
cpe:2.3:a:miniorange:oauth_single_sign_on:*:*:*:*:enterprise:wordpress:*:*
References (MISC) https://wpscan.com/vulnerability/52e29f16-b6dd-4132-9bb8-ad10bd3c39d7 - (MISC) https://wpscan.com/vulnerability/52e29f16-b6dd-4132-9bb8-ad10bd3c39d7 - Exploit, Third Party Advisory
References (MISC) https://wpscan.com/vulnerability/f6e165d9-2193-4c76-ae2d-618a739fe4fb - (MISC) https://wpscan.com/vulnerability/f6e165d9-2193-4c76-ae2d-618a739fe4fb - Exploit, Third Party Advisory
References (MISC) https://wpscan.com/vulnerability/5eb85df5-8aab-4f30-a401-f776a310b09c - (MISC) https://wpscan.com/vulnerability/5eb85df5-8aab-4f30-a401-f776a310b09c - Exploit, Third Party Advisory
References (MISC) https://wpscan.com/vulnerability/8fbf7efe-0bf2-42c6-aef1-7fcf2708b31b - (MISC) https://wpscan.com/vulnerability/8fbf7efe-0bf2-42c6-aef1-7fcf2708b31b - Exploit, Third Party Advisory

27 Mar 2023, 17:04

Type Values Removed Values Added
New CVE

Information

Published : 2023-03-27 16:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-1092

Mitre link : CVE-2023-1092

CVE.ORG link : CVE-2023-1092


JSON object : View

Products Affected

miniorange

  • oauth_single_sign_on
CWE

No CWE.