ZeroHour

CVE-2022-3511

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p52
Published
()
Modified
Description

The Awesome Support WordPress plugin before 6.1.2 does not ensure that the exported tickets archive to be downloaded belongs to the user making the request, allowing a low privileged user, such as subscriber to download arbitrary exported tickets via an IDOR vector

Vendors
getawesomesupport
Products
awesome support
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.