CVE-2022-25570

Publication date

2022-03-21 12:59:25

Family

mitre

State

PUBLISHED

Description

In Click Studios (SA) Pty Ltd Passwordstate 9435, users with access to a passwordlist can gain access to additional password lists without permissions. Specifically, an authenticated user who has write permissions to a password list in one folder (with the default permission model) can extend his permissions to all other password lists in the same folder.