CVE-2022-3875

HIGH

Click Studios Passwordstate - Auth Bypass

Title source: llm
STIX 2.1

Description

A vulnerability classified as critical was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. This vulnerability affects unknown code of the component API. The manipulation leads to authentication bypass by assumed-immutable data. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216244.

References (3)

Core 3

Scores

CVSS v3 7.3
EPSS 0.0097
EPSS Percentile 57.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-287 CWE-302
Status published
Products (1)
clickstudios/passwordstate (2 CPE variants)
Published Dec 19, 2022
Tracked Since Feb 18, 2026