CVE-2022-25570
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/03/2022
Last modified:
15/06/2022
Description
In Click Studios (SA) Pty Ltd Passwordstate 9435, users with access to a passwordlist can gain access to additional password lists without permissions. Specifically, an authenticated user who has write permissions to a password list in one folder (with the default permission model) can extend his permissions to all other password lists in the same folder.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:clickstudios:passwordstate:9.4:build_9435:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



