VDB
CVE-2024-49672
CVE-2024-49672
PUBLISHED
CVSS 7.099999904632568 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Gifford Cheung, Brian Watanabe, Chongsun Ahn Google Docs RSVP allows Stored XSS.This issue affects Google Docs RSVP: from n/a through 2.0.1.
EPSS 0.17% · 6.8th percentile
Risk Scores
CVSS 3.1
7.099999904632568
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
EPSS Score
0.17%
6.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gifford Cheung, Brian Watanabe, Chongsun Ahn | Google Docs RSVP | * |
| giffordcheung | Google Docs RSVP | 0 |
| gief | google_docs_rsvp | 0, 0 |
Timeline
- Oct 29, 2024 Coalition ESS Score
- Oct 29, 2024 Coalition ESS Score
- Oct 29, 2024 CVE Published
- Oct 29, 2024 PoC Published
- Oct 30, 2024 EPSS Score
- Nov 8, 2024 Coalition ESS Score
- Nov 17, 2024 EPSS Score
- Dec 7, 2024 EPSS Score
- Dec 25, 2024 EPSS Score
- Jan 12, 2025 EPSS Score
- Jan 31, 2025 EPSS Score
- Feb 18, 2025 EPSS Score
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-49672 advisory
- https://patchstack.com/database/Wordpress/Plugin/google-docs-rsvp-guestlist/vulnerability/wordpress-google-docs-rsvp-plugin-2-0-1-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve url
- https://patchstack.com/database/vulnerability/google-docs-rsvp-guestlist/wordpress-google-docs-rsvp-plugin-2-0-1-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve url