Lucene search

K
nvd[email protected]NVD:CVE-2023-47801
HistoryNov 13, 2023 - 9:15 a.m.

CVE-2023-47801

2023-11-1309:15:25
CWE-732
web.nvd.nist.gov
vulnerability
click studios
passwordstate
unauthorized access
deletion
api keys

4.7 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

0.0004 Low

EPSS

Percentile

13.3%

An issue was discovered in Click Studios Passwordstate before 9811. Existing users (Security Administrators) could use the System Wide API Key to read or delete private password records when specifically used with the PasswordHistory API endpoint. It is also possible to use the Copy/Move Password Record API Key to Copy/Move private password records.

Affected configurations

NVD
Node
clickstudiospasswordstateRange<9.8-

4.7 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

0.0004 Low

EPSS

Percentile

13.3%

Related for NVD:CVE-2023-47801