PT-2022-27693 · Mendix · Mendix Email Connector

Published

2022-12-13

·

Updated

2022-12-15

·

CVE-2022-45936

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Mendix Email Connector versions prior to 2.0.0
Description A vulnerability has been identified in the handling of access control for some module entities. This could allow authenticated remote attackers to read and manipulate sensitive information.
Recommendations For versions prior to 2.0.0, update to version 2.0.0 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information and module entities to minimize the risk of exploitation.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2022-45936

Affected Products

Mendix Email Connector