CVE-2022-43476

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 2, 2025
CWE ID 862

Summary

CVE-2022-43476 refers to a Missing Authorization vulnerability discovered in the Subscribe to Category feature of Daniel Söderström and Sidney van de Stouwe's plugin. This issue arises due to incorrectly configured access control security levels, enabling unauthorized users to exploit the vulnerability. The Subscribe to Category plugin, which affects versions 2.7.1 through 2.7.4, is the target of this exploit. This vulnerability poses a significant risk, as unauthorized access can lead to serious data breaches or system compromise. Users of the affected plugin are advised to apply the necessary patches or upgrades to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share