6.5
CVE-2022-25570
- EPSS 0.21%
- Veröffentlicht 21.03.2022 13:15:08
- Zuletzt bearbeitet 21.11.2024 06:52:22
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
In Click Studios (SA) Pty Ltd Passwordstate 9435, users with access to a passwordlist can gain access to additional password lists without permissions. Specifically, an authenticated user who has write permissions to a password list in one folder (with the default permission model) can extend his permissions to all other password lists in the same folder.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Clickstudios ≫ Passwordstate Version9.4 Updatebuild_9435
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.43 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
CWE-276 Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.