CVE Vulnerabilities

CVE-2023-1092

Published: Mar 27, 2023 | Modified: Nov 07, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The OAuth Single Sign On Free WordPress plugin before 6.24.2, OAuth Single Sign On Standard WordPress plugin before 28.4.9, OAuth Single Sign On Premium WordPress plugin before 38.4.9 and OAuth Single Sign On Enterprise WordPress plugin before 48.4.9 do not have CSRF checks when deleting Identity Providers (IdP), which could allow attackers to make logged in admins delete arbitrary IdP via a CSRF attack

Affected Software

Name Vendor Start Version End Version
Oauth_single_sign_on Miniorange * 6.24.2 (excluding)
Oauth_single_sign_on Miniorange * 28.4.9 (excluding)
Oauth_single_sign_on Miniorange * 38.4.9 (excluding)
Oauth_single_sign_on Miniorange * 48.4.9 (excluding)

References