CVE-2022-43476
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2022-43476 refers to a Missing Authorization vulnerability discovered in the Subscribe to Category feature of Daniel Söderström and Sidney van de Stouwe's plugin. This issue arises due to incorrectly configured access control security levels, enabling unauthorized users to exploit the vulnerability. The Subscribe to Category plugin, which affects versions 2.7.1 through 2.7.4, is the target of this exploit. This vulnerability poses a significant risk, as unauthorized access can lead to serious data breaches or system compromise. Users of the affected plugin are advised to apply the necessary patches or upgrades to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.