Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2mqw-xvh5-rv38

Опубликовано: 30 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.8

Описание

An Improper Access Control vulnerability has been found in EmbedAI

2.1 and below. This vulnerability allows an authenticated attacker to write messages into other users chat by changing the parameter "chat_id" of the POST request "/embedai/chats/send_message".

An Improper Access Control vulnerability has been found in EmbedAI

2.1 and below. This vulnerability allows an authenticated attacker to write messages into other users chat by changing the parameter "chat_id" of the POST request "/embedai/chats/send_message".

EPSS

Процентиль: 25%
0.00088
Низкий

5.8 Medium

CVSS3

Дефекты

CWE-284
CWE-863

Связанные уязвимости

CVSS3: 5.8
nvd
около 1 года назад

An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to write messages into other users chat by changing the parameter "chat_id" of the POST request "/embedai/chats/send_message".

EPSS

Процентиль: 25%
0.00088
Низкий

5.8 Medium

CVSS3

Дефекты

CWE-284
CWE-863