Description
The User Access Manager WordPress plugin before 2.2.18 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible for attackers to access restricted content in certain situations.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-24890 | The User Access Manager WordPress plugin before 2.2.18 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible for attackers to access restricted content in certain situations. |
References
History
Tue, 01 Oct 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-10-01T18:43:13.026Z
Reserved: 2022-05-05T19:19:57.374Z
Link: CVE-2022-1601
Updated: 2024-08-03T00:10:03.701Z
Status : Modified
Published: 2023-08-30T15:15:08.330
Modified: 2024-11-21T06:41:03.247
Link: CVE-2022-1601
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.
EUVD