8.8
CVE-2024-43982
- EPSS 0.63%
- Veröffentlicht 01.11.2024 15:15:51
- Zuletzt bearbeitet 08.11.2024 21:11:11
- Quelle audit@patchstack.com
- CVE-Watchlists
- Unerledigt
Login As Users <= 1.4.3 - Missing Authorization to Privielge Escalation via Account Takeover
Missing Authorization vulnerability in Geek Code Lab Login As Users allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Login As Users: from n/a through 1.4.3.
Mögliche Gegenmaßnahme
Login As Users: Update to version 1.4.4, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Login As Users
Version
*-1.4.3
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Geekcodelab ≫ Login As Users SwPlatformwordpress Version <= 1.4.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.63% | 0.696 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| audit@patchstack.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.