4.3

CVE-2023-39973

Extension - acymailing.com - Improper Access Control in AcyMailing Enterprise component for Joomla 6.7.0-8.6.3

Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. It allows the unauthorized removal of attachments from campaigns.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AcymailingAcymailing SwEditionenterprise SwPlatformjoomla! Version >= 6.7.0 < 8.7.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.33% 0.25
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

https://extensions.joomla.org/extension/acymailing-starter/
Product
https://www.acymailing.com/acymailing-release-security-%F0%9F%94%90-news-updates/
Vendor Advisory
Release Notes