CVE-2022-3511
Last modified
CVE-2022-3511 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. The Awesome Support WordPress plugin before 6.1.2 does not ensure that the exported tickets archive to be downloaded belongs to the user making the request, allowing a low privileged user, such as subscriber to download arbitrary exported tickets via an IDOR vector. EPSS estimates a 0.70% chance of exploitation in the next 30 days.
Description
The Awesome Support WordPress plugin before 6.1.2 does not ensure that the exported tickets archive to be downloaded belongs to the user making the request, allowing a low privileged user, such as subscriber to download arbitrary exported tickets via an IDOR vector
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Getawesomesupport | Awesome Support | < 6.1.2 |
References
- https://wpscan.com/vulnerability/9e57285a-0023-4711-874c-6e7b3c2673d1Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/9e57285a-0023-4711-874c-6e7b3c2673d1Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-3511?
How severe is CVE-2022-3511?
How do I fix CVE-2022-3511?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-35104SWFTools commit 772e55a2 was discovered to contain a heap-bu…5.5
- CVE-2022-35105SWFTools commit 772e55a2 was discovered to contain a heap-bu…5.5
- CVE-2022-35106SWFTools commit 772e55a2 was discovered to contain a segment…5.5
- CVE-2022-35107SWFTools commit 772e55a2 was discovered to contain a stack o…5.5
- CVE-2022-35108SWFTools commit 772e55a2 was discovered to contain a segment…5.5
- CVE-2022-35109SWFTools commit 772e55a2 was discovered to contain a heap-bu…5.5
- CVE-2022-35110SWFTools commit 772e55a2 was discovered to contain a memory …5.5
- CVE-2022-35111SWFTools commit 772e55a2 was discovered to contain a stack o…5.5
- CVE-2022-35113SWFTools commit 772e55a2 was discovered to contain a heap-bu…5.5
- CVE-2022-35114SWFTools commit 772e55a2 was discovered to contain a segment…5.5
- CVE-2022-35115IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) was disc…9.8
- CVE-2022-35117Clinic's Patient Management System v1.0 was discovered to co…4.8
Are you affected by CVE-2022-3511?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
