vulnrichment icon indicating copy to clipboard operation
vulnrichment copied to clipboard

CVE-2023-6892 Incorrect CPE, Vendor, Product, and Version

Open j-baines opened this issue 9 months ago • 0 comments

The CISA ADP has the wrong CPE/vendor/product for CVE-2023-6892. The vendor and product should be wpfactory and ean_for_woocommerce respectively. This is a different product from woocommerce:

  1. https://wordpress.org/plugins/ean-for-woocommerce/#description
  2. https://wordpress.org/plugins/woocommerce/

EAN for WooCommerce also has an existing CPE (see https://nvd.nist.gov/vuln/detail/CVE-2023-0062) so I swapped that in. Finally, the versions array said "*" or all versions are affected despite the CNA providing a reasonable version array. I've swapped in the CNA array.

j-baines avatar May 26 '24 10:05 j-baines