Lucene search

K
cve[email protected]CVE-2022-1656
HistoryJun 13, 2022 - 1:15 p.m.

CVE-2022-1656

2022-06-1313:15:11
CWE-284
web.nvd.nist.gov
2279
4
cve-2022-1656
jupiterx theme
vulnerability
unauthorized access
plugin deactivation
api key update
nvd

5.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:P/A:N

5.4 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

5.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.7%

Vulnerable versions of the JupiterX Theme (<=2.0.6) allow any logged-in user, including subscriber-level users, to access any of the functions registered in lib/api/api/ajax.php, which also grant access to the jupiterx_api_ajax_ actions registered by the JupiterX Core Plugin (<=2.0.6). This includes the ability to deactivate arbitrary plugins as well as update the theme’s API key.

Affected configurations

Vulners
NVD
Node
artbeesjupiter_x_coreRange2.0.6–2.0.6
OR
artbeesjupiter_x_coreRange2.0.6–2.0.6
VendorProductVersionCPE
artbeesjupiter_x_core*cpe:2.3:a:artbees:jupiter_x_core:*:*:*:*:*:*:*:*
artbeesjupiter_x_core*cpe:2.3:a:artbees:jupiter_x_core:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Jupiter X Core",
    "vendor": "ArtBees",
    "versions": [
      {
        "lessThanOrEqual": "2.0.6",
        "status": "affected",
        "version": "2.0.6",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "Jupiter X",
    "vendor": "ArtBees",
    "versions": [
      {
        "lessThanOrEqual": "2.0.6",
        "status": "affected",
        "version": "2.0.6",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

5.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:P/A:N

5.4 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

5.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.7%