SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-35934

The Advanced Access Manager plugin before 6.6.2 for WordPress displays the unfiltered user object (including all metadata) upon login via the REST API (aam/v1/authenticate or aam/v2/authenticate).

MEDIUM 4.3EPSS 1.06%

Does this matter?

Lower severity and a low EPSS score (1.06%). Track it; it rarely justifies an emergency change on its own.

Description

The Advanced Access Manager plugin before 6.6.2 for WordPress displays the unfiltered user object (including all metadata) upon login via the REST API (aam/v1/authenticate or aam/v2/authenticate). This is a security problem if this object stores information that the user is not supposed to have (e.g., custom metadata added by a different plugin).

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
1.06% probability · 63th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
vasyltech/advanced access manager
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.