2024-12-08 03:06:42 +00:00

94 lines
2.7 KiB
JSON

{
"id": "CVE-2022-3206",
"sourceIdentifier": "contact@wpscan.com",
"published": "2022-10-17T12:15:10.530",
"lastModified": "2024-11-21T07:19:02.963",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The Passster WordPress plugin before 3.5.5.5.2 stores the password inside a cookie named \"passster\" using base64 encoding method which is easy to decode. This puts the password at risk in case the cookies get leaked."
},
{
"lang": "es",
"value": "El plugin Passster de WordPress versiones anteriores a 3.5.5.2, almacena la contrase\u00f1a dentro de una cookie llamada \"passster\" usando el m\u00e9todo de codificaci\u00f3n base64 que es f\u00e1cil de decodificar. Esto pone en riesgo la contrase\u00f1a en caso de que las cookies sean filtradas"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "HIGH",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 2.2,
"impactScore": 3.6
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-319"
},
{
"lang": "en",
"value": "CWE-522"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:passster_project:passster:*:*:*:*:*:wordpress:*:*",
"versionEndExcluding": "3.5.5.5.2",
"matchCriteriaId": "CEA1E5C5-FE4A-4488-B0E0-0C931E87946C"
}
]
}
]
}
],
"references": [
{
"url": "https://wpscan.com/vulnerability/a8963750-62bf-403e-a906-94f371ed2a7a",
"source": "contact@wpscan.com",
"tags": [
"Exploit",
"Third Party Advisory"
]
},
{
"url": "https://wpscan.com/vulnerability/a8963750-62bf-403e-a906-94f371ed2a7a",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Exploit",
"Third Party Advisory"
]
}
]
}