CVE-2022-43472: WordPress eRoom plugin <= 1.4.6 - Broken Access Control vulnerability
Missing Authorization vulnerability in DigitalME eRoom eroom-zoom-meetings-webinar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects eRoom: from n/a through <= 1.4.6.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-43472?
CVE-2022-43472 is classified as a missing authorization vulnerability that could lead to unauthorized access to user data.
How do I fix CVE-2022-43472?
To fix CVE-2022-43472, update StylemixThemes eRoom – Zoom Meetings & Webinar to version 1.4.7 or later to ensure proper access controls are enforced.
What versions of eRoom are affected by CVE-2022-43472?
CVE-2022-43472 affects the StylemixThemes eRoom – Zoom Meetings & Webinar versions up to and including 1.4.6.
What types of attacks can exploit CVE-2022-43472?
Attackers can exploit CVE-2022-43472 to gain unauthorized access to restricted functionalities and potentially sensitive user data.
Is CVE-2022-43472 specific to a single software vendor?
CVE-2022-43472 specifically affects both StylemixThemes eRoom and WordPress eRoom versions up to 1.4.6, indicating it is relevant to multiple vendors.