5.4 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): Low (L)
- Integrity (I): Low (L)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): Low (L)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): None (N)
Activity log
- Created suggestion
WordPress Roam theme <= 2.1.1 - Insecure Direct Object References (IDOR) vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Roam roam allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Roam: from n/a through <= 2.1.1.
References
Affected products
- =<<= 2.1.1
Matching in nixpkgs
pkgs.geteduroam
GUI client to configure eduroam
pkgs.roam-research
Note-taking tool for networked thought
pkgs.geteduroam-cli
CLI client to configure eduroam
pkgs.easyroam-connect-desktop
Manage and install your easyroam WiFi profiles
Package maintainers
-
@MarchCraft Felix Nilles <felix@dienilles.de>
-
@manyinsects liv <shadows@with.al>
-
@pbsds Peder Bergebakken Sundt <pbsds@hotmail.com>
-
@viperML Fernando Ayats <ayatsfer@gmail.com>
-
@dbalan Dhananjay Balan <nix@dbalan.in>