CVE-2023-47801

MEDIUM

Clickstudios Passwordstate < 9.8 - Incorrect Permission Assignment

Title source: rule
STIX 2.1

Description

An issue was discovered in Click Studios Passwordstate before 9811. Existing users (Security Administrators) could use the System Wide API Key to read or delete private password records when specifically used with the PasswordHistory API endpoint. It is also possible to use the Copy/Move Password Record API Key to Copy/Move private password records.

References (1)

Core 1

Scores

CVSS v3 4.7
EPSS 0.0008
EPSS Percentile 23.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-732
Status published
Products (1)
clickstudios/passwordstate < 9.8
Published Nov 13, 2023
Tracked Since Feb 18, 2026