CVE-2022-0163

The Smart Forms WordPress plugin before 2.6.71 does not have authorisation in its rednao_smart_forms_entries_list AJAX action, allowing any authenticated users, such as subscriber, to download arbitrary form's data, which could include sensitive information such as PII depending on the form.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:rednao:smart_forms:*:*:*:*:*:wordpress:*:*

Information

Published : 2022-03-07 01:15

Updated : 2022-03-11 12:27


NVD link : CVE-2022-0163

Mitre link : CVE-2022-0163


JSON object : View

CWE
CWE-862

Missing Authorization

Advertisement

dedicated server usa

Products Affected

rednao

  • smart_forms