s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2023-32117

📛 CVE Title

WordPress Integrate Google Drive plugin <= 1.1.99 - Unauthenticated Broken Access Control vulnerability

Description

Missing Authorization vulnerability in SoftLab Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integrate Google Drive: from n/a through 1.1.99.

Overview

State
PUBLISHED
Assigner (CNA)
Patchstack
CVSS severity
CRITICAL
CVSS score
CVSS 9.8 / 10 9.8 9.8 / 10
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Effective score
9.8 / 10 CRITICAL source: CNA overview
CWE(s)
CWE-862
Reserved
2023-05-03
Published
2024-12-09 12:30 UTC
Last updated
2026-04-28 18:08 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/32xxx/CVE-2023-32117.json
Linked Threat
CVE-2023-32117 — Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2023-36385
Assigner
Patchstack
Published
Dec 9, 2024, 11:30:57 AM
Updated
Apr 28, 2026, 4:08:21 PM
EUVD base score (CVSS 3.1)
9.8 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EUVD-reported EPSS
89.3800
Vendors
princeahmed, SoftLab
Products
Integrate Google Drive (0 ≤1.1.99)
Integrate Google Drive (n/a ≤1.1.99)
Aliases
GHSA-fc7x-ffxp-c9q2

ENISA description: Missing Authorization vulnerability in SoftLab Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integrate Google Drive: from n/a through 1.1.99.

EUVD references (1)

Affected products (1)

VendorProductVersionsPlatforms
SoftLab Integrate Google Drive n/a (affected)

Vendor references (1)

References embedded in the original CVE record by the assigning CNA.

Web references (5)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

Indicators (2)

IOCs linked to the auto-promoted Threat row.

TypeValueVirusTotalAttached
domain levels.this no local data 2026-05-18 21:19 UTC
cve CVE-2023-32117 no local data 2026-06-06 15:01 UTC

Flagged vendors

    Remediations (23)

    Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

    • web:portal.msrc.microsoft.com

      The Microsoft Security Response Center (MSRC) investigates all reports of security vulnerabilities affecting Microsoft products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.

      2026-06-13 19:35 UTC
    • web:www.oracle.com

      Oracle Critical Patch Update Advisory - July 2025 Description A Critical Patch Update is a collection of patches for multiple security vulnerabilities. These patches address vulnerabilities in Oracle code and in third party components included in Oracle products. These patches are usually cumulative, but each advisory describes only the security patches added since the previous Critical Patch ...

      2026-06-13 19:35 UTC
    • web:www.hipaajournal.com

      CISA's solution is to patch smarter, not harder. CISA has released a new risk-based vulnerability remediation framework to help vendors assess vulnerabilities and prioritize patching effectively, concentrating their efforts on mitigating vulnerabilities in the most at-risk assets and addressing vulnerabilities that carry the greatest risk of ...

      2026-06-13 19:35 UTC
    • web:www.cisa.gov

      The median time for full resolution rose to 43 days. Defenders need greater clarity and speed to patch systems in today's threat landscape. We must flip the script on patching prioritization: patch smarter, not harder.

      2026-06-13 19:35 UTC
    • web:github.com

      CVEfixes: Automated Collection of Vulnerabilities and Their Fixes from Open-Source Software - secureIT-project/CVEfixes

      2026-06-13 19:35 UTC
    • Wordfence remediation: File Manager for Google Drive – Integrate Google Drive
      Wordfence

      Update to version 1.2.0, or a newer patched version

      2026-06-06 15:01 UTC
    • web:www.ninjaone.com

      The update is delivered through standard Windows Update channels and is recommended as part of regular maintenance routines. The patch resolves six distinct security vulnerabilities ranging from remote code execution to information disclosure issues, alongside reliability enhancements for Windows Communication Foundation (WCF) services.

      2026-05-22 06:30 UTC
    • web:github.com

      A new and improved community patch for BO3. . Contribute to shiversoftdev/t7patch development by creating an account on GitHub.

      2026-05-22 06:30 UTC
    • web:cyberpress.org

      A newly published proof-of-concept tool called BitUnlocker exposes a dangerous downgrade attack that can bypass Microsoft's BitLocker full-disk encryption on fully patched Windows 11 machines, granting complete access to encrypted drives in under five minutes. The attack exploits CVE -2025-48804, a vulnerability in Windows BitLocker that allows an attacker to mix untrusted data with trusted ...

      2026-05-22 06:30 UTC
    • web:www.pcworld.com

      Windows 11's Secure Boot fix update finally rolls out to more PCs Important security certificates for Windows 11 will soon expire for many users.

      2026-05-22 06:30 UTC
    • web:www.rapid7.com

      Microsoft is publishing 66 new vulnerabilities today, which is far fewer than we've come to expect in recent months. However, the lone zero-day vulnerability this month demands attention.

      2026-05-22 06:30 UTC
    • web:www.forbes.com

      Microsoft starts expiring critical Secure Boot certificates in just 2 weeks.

      2026-05-22 06:30 UTC
    • web:www.computerworld.com

      Each month, the team at Readiness analyzes the latest Patch Tuesday updates from Microsoft and provides detailed, actionable testing guidance. The company's Patch Tuesday release for February ...

      2026-05-22 06:30 UTC
    • web:www.oracle.com

      Critical Security Patch Updates Critical Security Patch Updates provide security patches for supported Oracle on-premises products. A Critical Security Patch Update provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption.

      2026-05-22 04:19 UTC
    • web:www.techrepublic.com

      Microsoft's April 2026 Patch Tuesday fixes 165 vulnerabilities, including two zero-days, in one of the company's largest monthly security updates.

      2026-05-22 04:19 UTC
    • web:heimdalsecurity.com

      Explore six essential patch management best practices for 2026 to keep your systems secure, up to date, and protected from vulnerabilities.

      2026-05-22 04:19 UTC
    • web:adaptiva.com

      Identify threats with CrowdStrike Exposure Management and fix vulnerabilities quickly with OneSite Patch . Prioritize deployments based on CrowdStrike's ExPRT.ai to ensure rapid remediation as soon as a patch is available.

      2026-05-22 04:19 UTC
    • web:help.eset.com

      Patch management helps ensure that systems and applications are secure against known vulnerabilities and exploits. The Patch management section lists all available patches remedying the detected vulnerabilities and makes the remediation process easier through automated software updates.

      2026-05-22 04:19 UTC
    • web:portal.msrc.microsoft.com

      The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

      2026-05-22 04:19 UTC
    • web:source.android.com

      This Section contains the available Android Security Bulletins, which provide fixes for possible issues affecting Android devices.

      2026-05-22 04:19 UTC
    • web:github.com

      Patch termsrv.dll so that multiple remote users can open an RDP session on a non-Windows Server computer - fabianosrc/TermsrvPatcher

      2026-05-22 04:19 UTC
    • web:www.cve.org

      At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures

      2026-05-22 04:19 UTC
    • web:cybersecuritynews.com

      Microsoft's May 2026 Patch Tuesday lands with a heavy enterprise focus, fixing 120 vulnerabilities across Windows, Office, Azure, developer tools, and Microsoft 365 apps, including 29 remote code execution (RCE) flaws rated Critical.

      2026-05-22 04:19 UTC

    AI Forensic Analysis

    Only Available for Registered Users. Sign in to view.

    Raw JSON

    The full cvelistV5 record. Download as CVE-2023-32117.json.

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:softlab:integrate_google_drive:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "integrate_google_drive",
                "vendor": "softlab",
                "versions": [
                  {
                    "lessThanOrEqual": "1.1.99",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-32117",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-12-09T16:46:27.207793Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-12-09T16:47:52.815Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unaffected",
              "packageName": "integrate-google-drive",
              "product": "Integrate Google Drive",
              "vendor": "SoftLab",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "1.2.0",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "1.1.99",
                  "status": "affected",
                  "version": "n/a",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Abdi Pranata (Patchstack Alliance)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "<p>Missing Authorization vulnerability in SoftLab Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels.</p><p>This issue affects Integrate Google Drive: from n/a through 1.1.99.</p>"
                }
              ],
              "value": "Missing Authorization vulnerability in SoftLab Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integrate Google Drive: from n/a through 1.1.99."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-180",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-180 Exploiting Incorrectly Configured Access Control Security Levels"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862 Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-04-28T16:08:21.890Z",
            "orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
            "shortName": "Patchstack"
          },
          "references": [
            {
              "tags": [
                "vdb-entry"
              ],
              "url": "https://patchstack.com/database/wordpress/plugin/integrate-google-drive/vulnerability/wordpress-integrate-google-drive-plugin-1-1-99-unauthenticated-broken-access-control-vulnerability?_s_id=cve"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Update the WordPress Integrate Google Drive plugin to the latest available version (at least 1.2.0)."
                }
              ],
              "value": "Update the WordPress Integrate Google Drive plugin to the latest available version (at least 1.2.0)."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "WordPress Integrate Google Drive plugin <= 1.1.99 - Unauthenticated Broken Access Control vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
        "assignerShortName": "Patchstack",
        "cveId": "CVE-2023-32117",
        "datePublished": "2024-12-09T11:30:57.774Z",
        "dateReserved": "2023-05-03T15:31:08.029Z",
        "dateUpdated": "2026-04-28T16:08:21.890Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }