PT-2022-27754 · Click Studios · Click Studios Passwordstate Browser Extension Chrome+1

·

CVE-2022-4613

·

Published

2022-12-19

·

Updated

2023-06-23

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Click Studios Passwordstate (affected versions not specified) Click Studios Passwordstate Browser Extension Chrome (affected versions not specified)
Description A critical issue affects the Browser Extension Provisioning component, leading to improper authorization. The attack can be initiated remotely. It is estimated that an unknown number of devices may be affected.
Recommendations To resolve the issue, upgrade the affected component. As a temporary workaround, consider restricting access to the Browser Extension Provisioning component until a patch is available.

Exploit

Fix

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-4613

Affected Products

Click Studios Passwordstate
Click Studios Passwordstate Browser Extension Chrome