Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
GoodMeet <= 1.1.8 - Cross-Site Request Forgery to Google Meet Credential Reset via 'goodmeet_reset_google_meet_credential'
Vulnerability Description
The GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.1.8. This is due to a missing nonce verification in the reset_credential() function, which handles the wp_ajax_goodmeet_reset_google_meet_credential AJAX action. While the function does verify the user's capability (manage_options), it does not validate a nonce, making it susceptible to CSRF attacks. This makes it possible for unauthenticated attackers to trick a site administrator into clicking a malicious link that will reset (delete) the plugin's stored Google Meet API credentials (goodmeet_google_credentials) and OAuth tokens (goodmeet_google_token), effectively disabling the Google Meet integration on the site.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Vulnerability Type
跨站请求伪造(CSRF)
Vulnerability Title
WordPress GoodMeet 跨站请求伪造漏洞
Vulnerability Description
WordPress GoodMeet是WordPress基金会的一款CMS组件。 WordPress GoodMeet 1.1.8及之前版本存在跨站请求伪造漏洞,该漏洞源于reset_credential()函数缺少随机数验证,容易受到跨站请求伪造攻击,可能导致未经身份验证的攻击者诱骗站点管理员点击恶意链接,重置并删除插件存储的Google Meet API凭据和OAuth令牌,从而禁用Google Meet集成。
CVSS Information
N/A
Vulnerability Type
N/A