Impact
A Cross‑Site Request Forgery flaw exists in the ShareThis Dashboard for Google Analytics plugin up to and including version 3.2.3. The vulnerability allows an attacker to craft a request that is executed with the privileges of a logged‑in user, potentially causing the user to perform unintended actions such as altering dashboard settings or submitting data. The flaw does not directly expose confidential data but permits unauthorized actions within the user’s session, which could be leveraged for further attacks. The weakness is identified as CWE‑352.
Affected Systems
The affected product is the ShareThis Dashboard for Google Analytics plugin from ShareThis. All installations of version 3.2.3 or earlier are vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% suggests an extremely low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The most likely attack path is a public web page or phishing email that tricks an authenticated user into submitting a malicious request, exploiting the lack of proper CSRF protection.
OpenCVE Enrichment
EUVD