Vulnerability Description
The KiviCare WordPress plugin before 3.2.1 does not have CSRF checks (either flawed or missing completely) in various AJAX actions, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks. This includes, but is not limited to: Delete arbitrary appointments/medical records/etc, create/update various users (patients, doctors etc)
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Iqonic | Kivicare | < 3.2.1 |
References
- https://wpscan.com/vulnerability/e0741e2c-c529-4815-8744-16e01cdb0aedExploitThird Party Advisory
- https://wpscan.com/vulnerability/e0741e2c-c529-4815-8744-16e01cdb0aedExploitThird Party Advisory
FAQ
What is CVE-2023-2628?
CVE-2023-2628 is a vulnerability with a CVSS score of 8.8 (HIGH). The KiviCare WordPress plugin before 3.2.1 does not have CSRF checks (either flawed or missing completely) in various AJAX actions, which could allow attackers to make logged in users perform unwanted...
How severe is CVE-2023-2628?
CVE-2023-2628 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-2628?
Check the references section above for vendor advisories and patch information. Affected products include: Iqonic Kivicare.