Lucene search

K
nvd[email protected]NVD:CVE-2022-3511
HistoryNov 28, 2022 - 2:15 p.m.

CVE-2022-3511

2022-11-2814:15:12
web.nvd.nist.gov
4
awesome support
wordpress
idor
vulnerability
unauthorized
ticket
downloads

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

32.8%

The Awesome Support WordPress plugin before 6.1.2 does not ensure that the exported tickets archive to be downloaded belongs to the user making the request, allowing a low privileged user, such as subscriber to download arbitrary exported tickets via an IDOR vector

Affected configurations

Nvd
Node
getawesomesupportawesome_supportRange<6.1.2wordpress
VendorProductVersionCPE
getawesomesupportawesome_support*cpe:2.3:a:getawesomesupport:awesome_support:*:*:*:*:*:wordpress:*:*

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

32.8%

Related for NVD:CVE-2022-3511