Lucene search

K
cve[email protected]CVE-2023-51499
HistoryApr 12, 2024 - 3:15 p.m.

CVE-2023-51499

2024-04-1215:15:22
CWE-862
web.nvd.nist.gov
49
cve-2023-51499
organization
individual
nvd
security problem
publicized

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

4.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Missing Authorization vulnerability in WooCommerce WooCommerce Shipping Per Product.This issue affects WooCommerce Shipping Per Product: from n/a through 2.5.4.

Affected configurations

Vulners
Node
woocommerceproduct_recommendationsRange2.5.4
VendorProductVersionCPE
woocommerceproduct_recommendations*cpe:2.3:a:woocommerce:product_recommendations:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "WooCommerce Shipping Per Product",
    "vendor": "WooCommerce",
    "versions": [
      {
        "changes": [
          {
            "at": "2.5.5",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "2.5.4",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

4.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Related for CVE-2023-51499