CVE-2024-6695 Vulnerability Details

  /     /     /  

CVE-2024-6695 Metadata Quick Info

CVE Published: 31/07/2024 | CVE Updated: 31/07/2024 | CVE Year: 2024
Source: WPScan | Vendor: Unknown | Product: User Profile Builder
Status : PUBLISHED

CVE-2024-6695 Description

it\'s possible for an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions. This is due to improper logic flow on the user registration process.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: CWE-287 Improper Authentication
Source: Unknown

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).