Missing Authentication for Critical Function in BP Social Connect - CVE-2023-2704
Published: June 14, 2024
Vulnerability details
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The vulnerability exists due to insufficient verification on the user being supplied during a Facebook login through the plugin. A remote unauthenticated attacker can bypass security restrictions on the target system and log in as any existing user on the site, such as an administrator.
Affected software
Storage Resource Manager
Dell EMC Storage Monitoring and Reporting (SMR)
How to mitigate CVE-2023-2704
Storage Resource Manager - update to 4.10.0.3
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.3
External References
- https://www.wordfence.com/threat-intel/vulnerabilities/id/44c96df2-530a-4ebe-b722-c606a7b135f9?source=cve
- https://plugins.trac.wordpress.org/browser/bp-social-connect/tags/1.5/includes/social/facebook/class.facebook.php#L138
- https://plugins.trac.wordpress.org/browser/bp-social-connect/tags/1.5/includes/social/facebook/class.facebook.php#L188
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=2914042%40bp-social-connect%2Ftrunk&old=1904372%40bp-social-connect%2Ftrunk&sfp_email=&sfph_mail=#file6
- https://lana.codes/lanavdb/1bd0dfd9-ffec-4d69-bc55-286751300cab/