PT-2022-27754 · Click Studios · Click Studios Passwordstate Browser Extension Chrome+1

Constantin Müller

+2

·

Published

2022-12-19

·

Updated

2023-06-23

·

CVE-2022-4613

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Click Studios Passwordstate (affected versions not specified) Click Studios Passwordstate Browser Extension Chrome (affected versions not specified)
Description A critical issue affects the Browser Extension Provisioning component, leading to improper authorization. The attack can be initiated remotely. It is estimated that an unknown number of devices may be affected.
Recommendations To resolve the issue, upgrade the affected component. As a temporary workaround, consider restricting access to the Browser Extension Provisioning component until a patch is available.

Exploit

Fix

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2022-4613

Affected Products

Click Studios Passwordstate
Click Studios Passwordstate Browser Extension Chrome