Lucene search

K
cvePatchstackCVE-2023-49774
HistoryJun 04, 2024 - 12:15 p.m.

CVE-2023-49774

2024-06-0412:15:09
CWE-200
Patchstack
web.nvd.nist.gov
18
cve-2023-49774
reserved
security problem
nvd

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

AI Score

7

Confidence

Low

EPSS

0

Percentile

9.0%

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Photo Album Plus: from n/a through 8.5.02.005.

Affected configurations

Vulners
Vulnrichment
Node
j.n._breetvelt_a.k.a._opajaapwp_photo_album_plusRange8.5.02.005wordpress
VendorProductVersionCPE
j.n._breetvelt_a.k.a._opajaapwp_photo_album_plus*cpe:2.3:a:j.n._breetvelt_a.k.a._opajaap:wp_photo_album_plus:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "collectionURL": "https://wordpress.org/plugins",
    "defaultStatus": "unaffected",
    "packageName": "wp-photo-album-plus",
    "product": "WP Photo Album Plus",
    "vendor": "J.N. Breetvelt a.k.a. OpaJaap",
    "versions": [
      {
        "changes": [
          {
            "at": "8.6.01.005",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "8.5.02.005",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

AI Score

7

Confidence

Low

EPSS

0

Percentile

9.0%