Known Vulnerabilities for products from Passwork
Listed below are 7 of the newest known vulnerabilities associated with the vendor "Passwork".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-49949 json | 8.1 - HIGH | 2023-12-26 | 2024-01-04 | |
| CVE-2022-42956 json | The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain the cleartext master password. | 7.5 - HIGH | 2022-11-07 | 2022-11-08 |
| CVE-2022-42955 json | The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain cleartext cached credentials. | 7.5 - HIGH | 2022-11-07 | 2022-11-08 |
| CVE-2022-25269 json | Passwork On-Premise Edition before 4.6.13 has multiple XSS issues. | 6.1 - MEDIUM | 2022-03-23 | 2022-03-29 |
| CVE-2022-25268 json | Passwork On-Premise Edition before 4.6.13 allows CSRF via the groups, password, and history subsystems. | 8.8 - HIGH | 2022-03-23 | 2022-03-29 |
| CVE-2022-25267 json | Passwork On-Premise Edition before 4.6.13 allows migration/uploadExportFile Directory Traversal (to upload files). | 8.8 - HIGH | 2022-03-23 | 2022-03-29 |
| CVE-2022-25266 json | Passwork On-Premise Edition before 4.6.13 allows migration/downloadExportFile Directory Traversal (to read files). | 4.3 - MEDIUM | 2022-03-23 | 2022-03-29 |