5.3
CVE-2022-0424
- EPSS 36.2%
- Veröffentlicht 09.05.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:38:35
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Popup by Supsystic <= 1.10.8 - Sensitive Information Disclosure
The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated attackers to call it and get the email addresses of subscribed users
Mögliche Gegenmaßnahme
Popup by Supsystic: Update to version 1.10.9, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Popup by Supsystic
Version
[*, 1.10.9)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 36.2% | 0.97 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.