CVE-2022-2552

The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site.
Configurations

Configuration 1 (hide)

cpe:2.3:a:snapcreek:duplicator:*:*:*:*:lite:wordpress:*:*

History

07 Nov 2023, 03:46

Type Values Removed Values Added
CWE CWE-862
CWE-306

04 Jul 2023, 10:15

Type Values Removed Values Added
CWE CWE-306

27 Jun 2023, 18:15

Type Values Removed Values Added
Summary The Duplicator WordPress plugin before 1.4.7.1 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site. The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site.
CWE CWE-306

23 Jun 2023, 18:24

Type Values Removed Values Added
CWE CWE-287 CWE-862
CWE-306

Information

Published : 2022-08-22 15:15

Updated : 2023-11-07 03:46


NVD link : CVE-2022-2552

Mitre link : CVE-2022-2552


JSON object : View

Products Affected

snapcreek

  • duplicator
CWE

No CWE.