6.5

CVE-2022-3930

Exploit

Directorist < 7.4.2.2 - Subscriber+ Arbitrary User Password Update via IDOR

Directorist <= 7.4.2.1 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Password Change

The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to change the password  of arbitrary users instead of his own.
Mögliche Gegenmaßnahme
Directorist: AI-Powered Business Directory, Listings & Classified Ads: Update to version 7.4.2.2, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WpwaxDirectorist SwPlatformwordpress Version < 7.4.2.2
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Directorist: AI-Powered Business Directory, Listings & Classified Ads
Version *-7.4.2.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.61% 0.443
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://wpscan.com/vulnerability/8728d02a-51db-4447-a843-0264b6ceb413
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/86ff2412-23c6-450e-b351-ba994d68aae6
Third Party Advisory