2023-12-20 20:00:51 +00:00
{
2024-05-17 09:00:47 +00:00
"data_version" : "4.0" ,
2023-12-20 20:00:51 +00:00
"data_type" : "CVE" ,
"data_format" : "MITRE" ,
"CVE_data_meta" : {
"ID" : "CVE-2023-51546" ,
2024-05-17 09:00:47 +00:00
"ASSIGNER" : "audit@patchstack.com" ,
"STATE" : "PUBLIC"
2023-12-20 20:00:51 +00:00
} ,
"description" : {
"description_data" : [
{
"lang" : "eng" ,
2024-05-17 09:00:47 +00:00
"value" : "Improper Privilege Management vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Privilege Escalation.This issue affects WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels: from n/a through 4.2.1."
}
]
} ,
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng" ,
"value" : "CWE-269 Improper Privilege Management" ,
"cweId" : "CWE-269"
}
]
}
]
} ,
"affects" : {
"vendor" : {
"vendor_data" : [
{
"vendor_name" : "WebToffee" ,
"product" : {
"product_data" : [
{
"product_name" : "WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels" ,
"version" : {
"version_data" : [
{
"version_value" : "not down converted" ,
"x_cve_json_5_version_data" : {
"versions" : [
{
"changes" : [
{
"at" : "4.3.0" ,
"status" : "unaffected"
}
] ,
"lessThanOrEqual" : "4.2.1" ,
"status" : "affected" ,
"version" : "n/a" ,
"versionType" : "custom"
}
] ,
"defaultStatus" : "unaffected"
}
}
]
}
}
]
}
}
]
}
} ,
"references" : {
"reference_data" : [
{
"url" : "https://patchstack.com/database/vulnerability/print-invoices-packing-slip-labels-for-woocommerce/wordpress-woocommerce-pdf-invoices-packing-slips-delivery-notes-and-shipping-labels-plugin-4-2-1-privilege-escalation-vulnerability?_s_id=cve" ,
"refsource" : "MISC" ,
"name" : "https://patchstack.com/database/vulnerability/print-invoices-packing-slip-labels-for-woocommerce/wordpress-woocommerce-pdf-invoices-packing-slips-delivery-notes-and-shipping-labels-plugin-4-2-1-privilege-escalation-vulnerability?_s_id=cve"
}
]
} ,
"generator" : {
"engine" : "Vulnogram 0.1.0-dev"
} ,
"source" : {
"discovery" : "EXTERNAL"
} ,
"solution" : [
{
"lang" : "en" ,
"supportingMedia" : [
{
"base64" : false ,
"type" : "text/html" ,
"value" : "Update to 4.3.0 or a higher version."
}
] ,
"value" : "Update to 4.3.0 or a higher version."
}
] ,
"credits" : [
{
"lang" : "en" ,
"value" : "Rafie Muhammad (Patchstack)"
}
] ,
"impact" : {
"cvss" : [
{
"attackComplexity" : "LOW" ,
"attackVector" : "NETWORK" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 7.2 ,
"baseSeverity" : "HIGH" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"privilegesRequired" : "HIGH" ,
"scope" : "UNCHANGED" ,
"userInteraction" : "NONE" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" ,
"version" : "3.1"
2023-12-20 20:00:51 +00:00
}
]
}
}