Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-32fr-75xx-54f3

Опубликовано: 18 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.7

Описание

The Sencore SMP100 SMP Media Platform (firmware versions V4.2.160, V60.1.4, V60.1.29) is vulnerable to session hijacking due to improper session management on the /UserManagement.html endpoint. Attackers who are on the same network as the victim and have access to the target's logged-in session can access the endpoint and add new users without any authentication. This allows attackers to gain unauthorized access to the system and perform malicious activities.

The Sencore SMP100 SMP Media Platform (firmware versions V4.2.160, V60.1.4, V60.1.29) is vulnerable to session hijacking due to improper session management on the /UserManagement.html endpoint. Attackers who are on the same network as the victim and have access to the target's logged-in session can access the endpoint and add new users without any authentication. This allows attackers to gain unauthorized access to the system and perform malicious activities.

EPSS

Процентиль: 11%
0.00038
Низкий

5.7 Medium

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 5.7
nvd
3 месяца назад

The Sencore SMP100 SMP Media Platform (firmware versions V4.2.160, V60.1.4, V60.1.29) is vulnerable to session hijacking due to improper session management on the /UserManagement.html endpoint. Attackers who are on the same network as the victim and have access to the target's logged-in session can access the endpoint and add new users without any authentication. This allows attackers to gain unauthorized access to the system and perform malicious activities.

EPSS

Процентиль: 11%
0.00038
Низкий

5.7 Medium

CVSS3

Дефекты

CWE-613