lana.codesThird-party advisoryTechnical description
https://lana.codes/lanavdb/071fa6eb-2e54-43a1-b37f-1e562988b7d4?_s_id=cve CVE-2022-34155
HIGH
WordPress OAuth Single Sign On – SSO (OAuth Client) Plugin <= 6.23.3 is vulnerable to Broken Authentication
Record summary
CVE-2022-34155 has a selected CVSS score of 8.8 (high); EIP currently links 1 repository PoC.
Description
Improper Authentication vulnerability in miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin allows Authentication Bypass.This issue affects OAuth Single Sign On – SSO (OAuth Client): from n/a through 6.23.3.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 25, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
OAuth Single Sign On – SSO (OAuth Client)Browse miniOrange / OAuth Single Sign On – SSO (OAuth Client)miniorange-login-with-eve-online-google-facebookDefault status: unaffected | CVE List | Through 6.23.3 | affected |
Proofs of concept
1Repository PoCs
GitHubvanh-88/CVE-2022-34155Repository PoCby vanh-88Stars: 0Not analyzed8 files
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-34155 patchstack.comvdb entry
https://patchstack.com/database/vulnerability/miniorange-login-with-eve-online-google-facebook/wordpress-oauth-single-sign-on-sso-oauth-client-plugin-6-23-3-broken-authentication-vulnerability?_s_id=cve