Information disclosure in Royal Elementor Addons - CVE-2023-3709

 

Information disclosure in Royal Elementor Addons - CVE-2023-3709

Published: July 20, 2023


Vulnerability identifier: #VU78452
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-3709
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to the affected plugin adds the API key to the source code of any page running the MailChimp block. A remote attacker can obtain a site's MailChimp API key.


Affected software

Royal Elementor Addons
Fedora
chromium

How to mitigate CVE-2023-3709

Install updates from vendor's website.

Royal Elementor Addons - update to 1.3.71
chromium - addressed in versions 114.0.5735.106-1.el7, 114.0.5735.106-1.el8, 114.0.5735.106-1.el9, 114.0.5735.106-1.fc37, 114.0.5735.106-1.fc38

External References

Related Security Bulletins