Updates CVE

This commit is contained in:
erwanlr 2022-02-17 19:43:43 +01:00
parent 78adcb20c6
commit 6615a1bcec

View File

@ -3,7 +3,7 @@
"ID": "CVE-2022-0633",
"ASSIGNER": "contact@wpscan.com",
"STATE": "PUBLIC",
"TITLE": "UpdraftPlus < 1.22.3 - Subscriber+ Backup Download"
"TITLE": "UpdraftPlus Free < 1.22.3 & Premium < 2.22.3 - Subscriber+ Backup Download"
},
"data_format": "MITRE",
"data_type": "CVE",
@ -13,11 +13,11 @@
"vendor": {
"vendor_data": [
{
"vendor_name": "Unknown",
"vendor_name": "UpdraftPlus",
"product": {
"product_data": [
{
"product_name": "UpdraftPlus WordPress Backup Plugin",
"product_name": "UpdraftPlus WordPress Backup Plugin (Free)",
"version": {
"version_data": [
{
@ -27,6 +27,18 @@
}
]
}
},
{
"product_name": "UpdraftPlus WordPress Backup Plugin (Premium)",
"version": {
"version_data": [
{
"version_affected": "<",
"version_name": "2.22.3",
"version_value": "2.22.3"
}
]
}
}
]
}
@ -38,7 +50,7 @@
"description_data": [
{
"lang": "eng",
"value": "The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.3 does not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download the most recent site & database backup."
"value": "The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download the most recent site & database backup."
}
]
},