Lucene search

K
cvePatchstackCVE-2023-36676
HistoryJun 19, 2024 - 2:15 p.m.

CVE-2023-36676

2024-06-1914:15:11
CWE-862
Patchstack
web.nvd.nist.gov
27
authorization
brainstorm force
spectra
vulnerability
versions

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

20.0%

Missing Authorization vulnerability in Brainstorm Force Spectra.This issue affects Spectra: from n/a through 2.6.6.

Affected configurations

Nvd
Vulners
Node
brainstormforcespectraRange<2.6.7wordpress
VendorProductVersionCPE
brainstormforcespectra*cpe:2.3:a:brainstormforce:spectra:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "collectionURL": "https://wordpress.org/plugins",
    "defaultStatus": "unaffected",
    "packageName": "ultimate-addons-for-gutenberg",
    "product": "Spectra",
    "vendor": "Brainstorm Force",
    "versions": [
      {
        "changes": [
          {
            "at": "2.6.7",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "2.6.6",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

20.0%

Related for CVE-2023-36676