CVE-2022-1663 Vulnerability Details
/
/
/
CVE-2022-1663 Metadata Quick Info
CVE Published: 29/08/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022
Source: WPScan |
Vendor: Unknown |
Product: Stop Spam Comments
Status : PUBLISHED
CVE-2022-1663 Description
The Stop Spam Comments WordPress plugin through 0.2.1.2 does not properly generate the Javascript access token for preventing abuse of comment section, allowing threat authors to easily collect the value and add it to the request.
Metrics
CVSS Version: 3.1 |
Base Score: n/a
Vector: n/a
l➤ Exploitability Metrics:
Attack Vector (AV)*
Attack Complexity (AC)*
Privileges Required (PR)*
User Interaction (UI)*
Scope (S)*
l➤ Impact Metrics:
Confidentiality Impact (C)*
Integrity Impact (I)*
Availability Impact (A)*
Weakness Enumeration (CWE)
CWE-ID: CWE-200
CWE Name: CWE-200 Information Exposure
Source: Unknown
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID:
CAPEC Description:
Source: NVD (National Vulnerability Database).