{ "id": "CVE-2022-22111", "sourceIdentifier": "vulnerabilitylab@mend.io", "published": "2022-01-05T15:15:07.990", "lastModified": "2024-11-21T06:46:12.273", "vulnStatus": "Modified", "cveTags": [], "descriptions": [ { "lang": "en", "value": "In DayByDay CRM, version 2.2.0 is vulnerable to missing authorization. Any application user in the application who has update user permission enabled is able to change the password of other users, including the administrator\u2019s. This allows the attacker to gain access to the highest privileged user in the application." }, { "lang": "es", "value": "En DayByDay CRM, versi\u00f3n 2.2.0, es vulnerable a una falta de autorizaci\u00f3n. Cualquier usuario de la aplicaci\u00f3n que tenga habilitado el permiso de actualizaci\u00f3n de usuarios es capaz de cambiar la contrase\u00f1a de otros usuarios, incluida la del administrador. Esto permite al atacante conseguir acceso al usuario con m\u00e1s privilegios de la aplicaci\u00f3n." } ], "metrics": { "cvssMetricV31": [ { "source": "vulnerabilitylab@mend.io", "type": "Secondary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 8.8, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" }, "exploitabilityScore": 2.8, "impactScore": 5.9 }, { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 8.8, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" }, "exploitabilityScore": 2.8, "impactScore": 5.9 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P", "baseScore": 6.5, "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "SINGLE", "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "availabilityImpact": "PARTIAL" }, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.0, "impactScore": 6.4, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "vulnerabilitylab@mend.io", "type": "Secondary", "description": [ { "lang": "en", "value": "CWE-862" } ] }, { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-862" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:daybydaycrm:daybyday_crm:2.2.0:*:*:*:*:*:*:*", "matchCriteriaId": "B1A83CDA-4210-4151-BAAC-F16FA2DAAB4C" } ] } ] } ], "references": [ { "url": "https://github.com/Bottelet/DaybydayCRM/commit/fe842ea5ede237443f1f45a99aeb839133115d8b", "source": "vulnerabilitylab@mend.io", "tags": [ "Patch", "Third Party Advisory" ] }, { "url": "https://www.whitesourcesoftware.com/vulnerability-database/CVE-2022-22111", "source": "vulnerabilitylab@mend.io", "tags": [ "Third Party Advisory" ] }, { "url": "https://github.com/Bottelet/DaybydayCRM/commit/fe842ea5ede237443f1f45a99aeb839133115d8b", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Patch", "Third Party Advisory" ] }, { "url": "https://www.whitesourcesoftware.com/vulnerability-database/CVE-2022-22111", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ] } ] }