6.5
CVSSv3

CVE-2022-3511

Published: 28/11/2022 Updated: 07/11/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The Awesome Support WordPress plugin prior to 6.1.2 does not ensure that the exported tickets archive to be downloaded belongs to the user making the request, allowing a low privileged user, such as subscriber to download arbitrary exported tickets via an IDOR vector

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

getawesomesupport awesome support