Lucene search

K
cve[email protected]CVE-2022-44411
HistoryNov 25, 2022 - 4:15 p.m.

CVE-2022-44411

2022-11-2516:15:10
CWE-319
web.nvd.nist.gov
28
10
cve-2022-44411
web based quiz system
plaintext password
authentication
bruteforce
nvd

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

58.8%

Web Based Quiz System v1.0 transmits user passwords in plaintext during the authentication process, allowing attackers to obtain users’ passwords via a bruteforce attack.

Affected configurations

NVD
Node
web_based_quiz_system_projectweb_based_quiz_systemMatch1.0

Social References

More

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

58.8%

Related for CVE-2022-44411