PT-2022-23295 · Jumpdemand · Activedemand

Nguyen Anh Tien

+1

·

Published

2022-08-05

·

Updated

2024-09-17

·

CVE-2022-36296

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions JumpDEMAND Inc. ActiveDEMAND plugin versions <= 0.2.27
Description The issue concerns a Broken Authentication vulnerability. It allows unauthenticated users to update, create, or delete posts.
Recommendations For JumpDEMAND Inc. ActiveDEMAND plugin versions <= 0.2.27, update to a version higher than 0.2.27 to resolve the issue.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2022-36296

Affected Products

Activedemand