Lucene search

K
cveMitreCVE-2022-47034
HistoryFeb 13, 2023 - 10:15 p.m.

CVE-2022-47034

2023-02-1322:15:13
CWE-697
mitre
web.nvd.nist.gov
34
cve-2022-47034
type juggling
vulnerability
playsms
authentication bypass
nvd

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.3

Confidence

High

EPSS

0.002

Percentile

60.8%

A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass authentication.

Affected configurations

Nvd
Node
playsmsplaysmsRange1.4.5
VendorProductVersionCPE
playsmsplaysms*cpe:2.3:a:playsms:playsms:*:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.3

Confidence

High

EPSS

0.002

Percentile

60.8%

Related for CVE-2022-47034