CVE-2022-25570

MEDIUM

Click Studios Passwordstate 9435 - Authenticated Permission Escalation via Default Permission Model

Title source: llm
STIX 2.1

Description

In Click Studios (SA) Pty Ltd Passwordstate 9435, users with access to a passwordlist can gain access to additional password lists without permissions. Specifically, an authenticated user who has write permissions to a password list in one folder (with the default permission model) can extend his permissions to all other password lists in the same folder.

Scores

CVSS v3 6.5
EPSS 0.0081
EPSS Percentile 52.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-276
Status published
Products (1)
clickstudios/passwordstate 9.4 build_9435
Published Mar 21, 2022
Tracked Since Feb 18, 2026