Lucene search

K
cve[email protected]CVE-2023-47801
HistoryNov 13, 2023 - 9:15 a.m.

CVE-2023-47801

2023-11-1309:15:25
CWE-732
web.nvd.nist.gov
11
click studios
passwordstate
cve-2023-47801
api key
security administrators
password records

4.7 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

4.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.3%

An issue was discovered in Click Studios Passwordstate before 9811. Existing users (Security Administrators) could use the System Wide API Key to read or delete private password records when specifically used with the PasswordHistory API endpoint. It is also possible to use the Copy/Move Password Record API Key to Copy/Move private password records.

Affected configurations

NVD
Node
clickstudiospasswordstateRange<9.8-

4.7 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

4.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.3%

Related for CVE-2023-47801