Vulnerabilities > CVE-2022-46850 - Missing Authorization vulnerability in Easy Media Replace Project Easy Media Replace

047910
CVSS 8.1 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
easy-media-replace-project
CWE-862

Summary

Auth. (author+) Broken Access Control vulnerability leading to Arbitrary File Deletion in Nabil Lemsieh Easy Media Replace plugin <= 0.1.3 versions.

Vulnerable Configurations

Part Description Count
Application
Easy_Media_Replace_Project
1

Common Weakness Enumeration (CWE)