Security Advisory

CVE-2022-25570

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-03-21 12:59:25
Last updated 2024-08-03 04:42:50
Assigner mitre
State PUBLISHED

Description

In Click Studios (SA) Pty Ltd Passwordstate 9435, users with access to a passwordlist can gain access to additional password lists without permissions. Specifically, an authenticated user who has write permissions to a password list in one folder (with the default permission model) can extend his permissions to all other password lists in the same folder.