Information disclosure in Royal Elementor Addons - CVE-2023-3709
Published: July 20, 2023
Vulnerability identifier: #VU78452
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-3709
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the affected plugin adds the API key to the source code of any page running the MailChimp block. A remote attacker can obtain a site's MailChimp API key.
Affected software
Royal Elementor Addons
Fedora
chromium
Fedora
chromium
How to mitigate CVE-2023-3709
Install updates from vendor's website.
Royal Elementor Addons - update to 1.3.71
chromium - addressed in versions 114.0.5735.106-1.el7, 114.0.5735.106-1.el8, 114.0.5735.106-1.el9, 114.0.5735.106-1.fc37, 114.0.5735.106-1.fc38
chromium - addressed in versions 114.0.5735.106-1.el7, 114.0.5735.106-1.el8, 114.0.5735.106-1.el9, 114.0.5735.106-1.fc37, 114.0.5735.106-1.fc38