CVE-2023-2623

Severity
6.5MEDIUM
EPSS
0.3%
top 42.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 27

Description

The KiviCare WordPress plugin before 3.2.1 does not restrict the information returned in a response and returns all user data, allowing low privilege users such as subscriber to retrieve sensitive information such as the user email and hashed password of other users

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDiqonic/kivicare< 3.2.1
CVEListV5unknown/kivicare< 3.2.1

🔴Vulnerability Details

2
CVEList
KiviCare Management System < 3.2.1 - Subscriber+ Sensitive Information Disclosure2023-06-27
GHSA
GHSA-c75r-2gqr-7xhr: The KiviCare WordPress plugin before 32023-06-27
CVE-2023-2623 (MEDIUM CVSS 6.5) | The KiviCare WordPress plugin befor | cvebase.io