Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-276w-gj4p-9x23

Опубликовано: 05 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset mechanism is mishandled. Making both a GET and a POST request to login.php.is sufficient. An unauthenticated attacker can then bypass authentication via administrator account takeover.

In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset mechanism is mishandled. Making both a GET and a POST request to login.php.is sufficient. An unauthenticated attacker can then bypass authentication via administrator account takeover.

EPSS

Процентиль: 53%
0.003
Низкий

7.5 High

CVSS3

Дефекты

CWE-684

Связанные уязвимости

CVSS3: 7.5
nvd
около 1 месяца назад

In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset mechanism is mishandled. Making both a GET and a POST request to login.php.is sufficient. An unauthenticated attacker can then bypass authentication via administrator account takeover.

EPSS

Процентиль: 53%
0.003
Низкий

7.5 High

CVSS3

Дефекты

CWE-684