Lucene search

K
nvd[email protected]NVD:CVE-2022-4107
HistoryDec 19, 2022 - 2:15 p.m.

CVE-2022-4107

2022-12-1914:15:12
web.nvd.nist.gov
3
smsa shipping
woocommerce
wordpress
plugin
authorization
csrf
arbitrary file access

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

61.6%

The SMSA Shipping for WooCommerce WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks, as well as does not validate the file to be downloaded, allowing any authenticated users, such as subscriber to download arbitrary file from the server

Affected configurations

Nvd
Node
cedcommercesmsa_shipping_for_woocommerceRange<1.0.5wordpress
VendorProductVersionCPE
cedcommercesmsa_shipping_for_woocommerce*cpe:2.3:a:cedcommerce:smsa_shipping_for_woocommerce:*:*:*:*:*:wordpress:*:*

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

61.6%