9.1

CVE-2022-0482

Exploit

Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments

Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
EasyappointmentsEasyappointments SwPlatformwordpress Version < 1.4.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 38.13% 0.984
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
security@huntr.dev 9.1 3.9 5.2
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE-359 Exposure of Private Personal Information to an Unauthorized Actor

The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

http://packetstormsecurity.com/files/166701/Easy-Appointments-Information-Disclosure.html
Third Party Advisory
Exploit
VDB Entry
https://github.com/alextselegidis/easyappointments/commit/44af526a6fc5e898bc1e0132b2af9eb3a9b2c466
Patch
Third Party Advisory
https://huntr.dev/bounties/2fe771ef-b615-45ef-9b4d-625978042e26
Patch
Third Party Advisory
Exploit
https://opencirt.com/hacking/securing-easy-appointments-cve-2022-0482/
Third Party Advisory