CVE-2022-1903

Scores

EPSS

0.826high82.6%
0%20%40%60%80%100%

Percentile: 82.6%

CVSS

8.1high3.x
0246810

CVSS Score: 8.1/10

All CVSS Scores

CVSS 3.x
8.1

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS 2.0
6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Description

The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and authorization checks in an AJAX action available to unauthenticated users, allowing them to change the password of arbitrary users by knowing their username

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-862

Exploits

Exploit ID: CVE-2022-1903

Source: github-poc

URL: https://github.com/biulove0x/CVE-2022-1903

Vulnerable Software (1)

Type: Configuration

Vendor: *

Product: armember

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:armemberplugin:armember:*:*:*:*:*:wordpress:*:*",      "versionEndExcluding": "3.4.8",      "vulnerable": true    }  ],  "operator": "OR"}

Source: nvd

End of list