Lucene search

K
cve[email protected]CVE-2023-49812
HistoryDec 19, 2023 - 9:15 p.m.

CVE-2023-49812

2023-12-1921:15:09
CWE-639
web.nvd.nist.gov
41
cve
2023
49812
authorization bypass
user-controlled key
j.n. breetvelt
opajaap
wp photo album plus

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

37.3%

Authorization Bypass Through User-Controlled Key vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a through 8.5.02.005.

Affected configurations

Vulners
NVD
Node
j.n._breetvelt_a.k.a._opajaapwp_photo_album_plusRange8.5.02.005

CNA Affected

[
  {
    "collectionURL": "https://wordpress.org/plugins",
    "defaultStatus": "unaffected",
    "packageName": "wp-photo-album-plus",
    "product": "WP Photo Album Plus",
    "vendor": "J.N. Breetvelt a.k.a. OpaJaap",
    "versions": [
      {
        "lessThanOrEqual": "8.5.02.005",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

37.3%

Related for CVE-2023-49812