What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Etison, LLC ClickFunnels plugin <= 3.1.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Etison, LLC ClickFunnels plugin <= 3.1.1 versions.
Explanation of Vulnerability in Simple Terms
ClickFunnels versions up to 3.1.1 are vulnerable to cross-site request forgery (CSRF) attacks. An attacker can craft a malicious webpage that, when visited by a logged-in ClickFunnels user, performs unwanted actions on their account without their knowledge. The attack requires the user to visit the attacker's page while authenticated to ClickFunnels.
What an attacker can do
Perform unwanted actions on a user's ClickFunnels account without their consent.
Potential impact on your site
Users' ClickFunnels accounts can be modified or data altered if they visit untrusted websites while logged in.
Conditions required to exploit
The victim must be logged into ClickFunnels and visit a malicious webpage controlled by the attacker.
Key dates
External resources
Related vulnerabilities