Lucene search

K
cvePatchstackCVE-2022-36388
HistorySep 23, 2022 - 3:15 p.m.

CVE-2022-36388

2022-09-2315:15:13
CWE-352
Patchstack
web.nvd.nist.gov
38
2
cve-2022-36388
cross-site request forgery
csrf
yds support ticket system
wordpress
vulnerability
nvd

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

41.8%

Cross-Site Request Forgery (CSRF) vulnerability in YDS Support Ticket System plugin <= 1.0 at WordPress.

Affected configurations

Nvd
Vulners
Node
ydesignservicesyds_support_ticket_systemRange1.0wordpress
VendorProductVersionCPE
ydesignservicesyds_support_ticket_system*cpe:2.3:a:ydesignservices:yds_support_ticket_system:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "product": "YDS Support Ticket System (WordPress plugin)",
    "vendor": "Ydesignservices",
    "versions": [
      {
        "lessThanOrEqual": "1.0",
        "status": "affected",
        "version": "<= 1.0",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

41.8%