Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2rhx-q7hx-f25r

Опубликовано: 07 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.1

Описание

Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstate allows attackers to access documents uploaded by landlords or tenants without authorization.

This issue affects MicroRealEstate: through 1.0.0-alpha3.

Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstate allows attackers to access documents uploaded by landlords or tenants without authorization.

This issue affects MicroRealEstate: through 1.0.0-alpha3.

EPSS

Процентиль: 29%
0.00364
Низкий

7.1 High

CVSS4

Дефекты

CWE-639

Связанные уязвимости

nvd
2 месяца назад

Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstate allows attackers to access documents uploaded by landlords or tenants without authorization. This issue affects MicroRealEstate: through 1.0.0-alpha3.

EPSS

Процентиль: 29%
0.00364
Низкий

7.1 High

CVSS4

Дефекты

CWE-639