CVE-2022-25570

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/03/2022
Last modified:
15/06/2022

Description

In Click Studios (SA) Pty Ltd Passwordstate 9435, users with access to a passwordlist can gain access to additional password lists without permissions. Specifically, an authenticated user who has write permissions to a password list in one folder (with the default permission model) can extend his permissions to all other password lists in the same folder.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:clickstudios:passwordstate:9.4:build_9435:*:*:*:*:*:*