Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-3511

Опубликовано: 28 нояб. 2022
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

The Awesome Support WordPress plugin before 6.1.2 does not ensure that the exported tickets archive to be downloaded belongs to the user making the request, allowing a low privileged user, such as subscriber to download arbitrary exported tickets via an IDOR vector

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:getawesomesupport:awesome_support:*:*:*:*:*:wordpress:*:*
Версия до 6.1.2 (исключая)

EPSS

Процентиль: 51%
0.00276
Низкий

6.5 Medium

CVSS3

Дефекты

Связанные уязвимости

CVSS3: 6.5
github
больше 2 лет назад

The Awesome Support WordPress plugin before 6.1.2 does not ensure that the exported tickets archive to be downloaded belongs to the user making the request, allowing a low privileged user, such as subscriber to download arbitrary exported tickets via an IDOR vector

EPSS

Процентиль: 51%
0.00276
Низкий

6.5 Medium

CVSS3

Дефекты