cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forintegrate-google-drive integrate-google-drive

Direction: ascending
Jun 07, 2024

Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Y # CVE-2024-2086

CVE, Research URL

CVE-2024-2086

Date
Mar 30, 2024
Research Description
The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on multiple AJAX in all versions up to, and including, 1.3.8. This makes it possible for authenticated attackers to modify plugin settings as well as allowing full read/write/delete access to the Google Drive associated with the plugin.
Affected versions
Min -, max -.
Status
vulnerable

Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Y # 0cca1604a3b4913bf0af2007223bcbc35bd3c970

Date
Feb 28, 2022
Research Description
File Manager for Google Drive &#8211; Integrate Google Drive with WordPress [integrate-google-drive] < 1.1.0 WordPress Integrate Google Drive – Complete Google Drive Cloud Solution For WordPress plugin < 1.1.0 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Integrate Google Drive – Complete Google Drive Cloud Solution For WordPress plugin (versions < 1.1.0).
Affected versions
Min -, max -.
Status
vulnerable

Integrate Google Drive &#8211; Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Y # CVE-2023-47548

CVE, Research URL

CVE-2023-47548

Date
Dec 07, 2023
Research Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SoftLab Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site.This issue affects Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site: from n/a through 1.3.2.
Affected versions
Min -, max -.
Status
vulnerable
Jun 10, 2024

Integrate Google Drive &#8211; Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Y # CVE-2023-32117

CVE, Research URL

CVE-2023-32117

Date
Dec 09, 2024
Research Description
Missing Authorization vulnerability in SoftLab Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integrate Google Drive: from n/a through 1.1.99.
Affected versions
Min -, max -.
Status
vulnerable
Nov 16, 2024

Integrate Google Drive &#8211; Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Y # CVE-2022-4974

CVE, Research URL

CVE-2022-4974

Date
Oct 16, 2024
Research Description
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Affected versions
Min -, max -.
Status
vulnerable