Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Codection Import and export users and customers allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Import and export users and customers: from n/a through 1.26.8.
History

Wed, 14 Aug 2024 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Codection
Codection import And Export Users And Customers
CPEs cpe:2.3:a:codection:import_and_export_users_and_customers:*:*:*:*:*:wordpress:*:*
Vendors & Products Codection
Codection import And Export Users And Customers
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 13 Aug 2024 10:45:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Codection Import and export users and customers allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Import and export users and customers: from n/a through 1.26.8.
Title WordPress Import and export users and customers plugin <= 1.26.8 - Sensitive Information via Imported File vulnerability
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published: 2024-08-13T10:33:21.336Z

Updated: 2024-08-14T18:28:29.746Z

Reserved: 2024-06-19T15:07:57.035Z

Link: CVE-2024-38787

cve-icon Vulnrichment

Updated: 2024-08-14T18:28:12.044Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-08-13T11:15:17.080

Modified: 2024-08-13T12:58:25.437

Link: CVE-2024-38787

cve-icon Redhat

No data.