CVE-2022-2133 Vulnerability Details

  /     /     /  

CVE-2022-2133 Metadata Quick Info

CVE Published: 17/07/2022 | CVE Updated: 03/08/2024 | CVE Year: 2022
Source: WPScan | Vendor: Unknown | Product: OAuth Single Sign On – SSO (OAuth Client)
Status : PUBLISHED

CVE-2022-2133 Description

The OAuth Single Sign On WordPress plugin before 6.22.6 doesn\'t validate that OAuth access token requests are legitimate, which allows attackers to log onto the site with the only knowledge of a user\'s email address.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-287
CWE Name: CWE-287 Improper Authentication
Source: Unknown

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).