CVE Vulnerabilities

CVE-2022-1654

Improper Privilege Management

Published: Jun 13, 2022 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Jupiter Theme <= 6.10.1 and JupiterX Core Plugin <= 2.0.7 allow any authenticated attacker, including a subscriber or customer-level attacker, to gain administrative privileges via the abb_uninstall_template (both) and jupiterx_core_cp_uninstall_template (JupiterX Core Only) AJAX actions

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Jupiter Artbees * 6.10.1 (including)
Jupiterx Artbees * 2.0.7 (including)

Potential Mitigations

References