PT-2022-27754 · Click Studios · Click Studios Passwordstate Browser Extension Chrome+1
Constantin Müller
+2
·
Published
2022-12-19
·
Updated
2023-06-23
·
CVE-2022-4613
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Click Studios Passwordstate (affected versions not specified)
Click Studios Passwordstate Browser Extension Chrome (affected versions not specified)
Description
A critical issue affects the Browser Extension Provisioning component, leading to improper authorization. The attack can be initiated remotely. It is estimated that an unknown number of devices may be affected.
Recommendations
To resolve the issue, upgrade the affected component.
As a temporary workaround, consider restricting access to the Browser Extension Provisioning component until a patch is available.
Exploit
Fix
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Click Studios Passwordstate
Click Studios Passwordstate Browser Extension Chrome