7.5
CVE-2024-38787
- EPSS 1.49%
- Veröffentlicht 13.08.2024 11:15:17
- Zuletzt bearbeitet 13.08.2024 12:58:25
- Quelle audit@patchstack.com
- CVE-Watchlists
- Unerledigt
Import and export users and customers <= 1.26.8 - Unauthenticated Information Exposure
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Codection Import and export users and customers allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Import and export users and customers: from n/a through 1.26.8.
Mögliche Gegenmaßnahme
Import and export users and customers: Update to version 1.26.9, or a newer patched version
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Import and export users and customers
Version
*-1.26.8
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
Herstellercodection
≫
Produkt
import_and_export_users_and_customers
Default Statusunknown
Version <=
1.26.8
Version
0
Status
affected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.49% | 0.807 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| audit@patchstack.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.