Lucene search

K
cvePatchstackCVE-2023-46146
HistoryJun 19, 2024 - 12:15 p.m.

CVE-2023-46146

2024-06-1912:15:10
CWE-862
Patchstack
web.nvd.nist.gov
38
cve
2023
46146
reserved
organization
individual
security
nvd

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.3

Confidence

High

EPSS

0.001

Percentile

20.0%

Missing Authorization vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.

Affected configurations

Nvd
Vulners
Node
themifyultraRange<7.3.6wordpress
VendorProductVersionCPE
themifyultra*cpe:2.3:a:themify:ultra:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Themify Ultra",
    "vendor": "Themify",
    "versions": [
      {
        "changes": [
          {
            "at": "7.3.6",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "7.3.5",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.3

Confidence

High

EPSS

0.001

Percentile

20.0%