9.1
CVSSv3

CVE-2022-26629

Published: 24/03/2022 Updated: 31/03/2022
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 571
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

An Access Control vulnerability exists in SoroushPlus+ Messenger 1.0.30 in the Lock Screen Security Feature function due to insufficient permissions and privileges, which allows a malicious attacker bypass the lock screen function.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

splus soroushplus 1.0.30

Github Repositories

Lock Screen Bypass CVE-2022-26629 Affected Products SoroushPlus+ Messenger 1030 Vulnerability Type Improper Access Control Impact Lock Screen Bypass Summary Improper handling of insufficient permissions and privileges allows an attacker to modify and overwrite the lock screen functionality causing it to be bypassed without any authorization Exploitation BypassLockScreenpy

Lock Screen Bypass CVE-2022-26629 Affected Products SoroushPlus+ Messenger 1030 Vulnerability Type Improper Access Control Impact Lock Screen Bypass Summary Improper handling of insufficient permissions and privileges allows an attacker to modify and overwrite the lock screen functionality causing it to be bypassed without any authorization Exploitation BypassLockScreenpy