Описание
Incorrect access control in the REST API endpoint of HubSpot v1.29441 allows unauthenticated attackers to view users' data without proper authorization.
Incorrect access control in the REST API endpoint of HubSpot v1.29441 allows unauthenticated attackers to view users' data without proper authorization.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2023-37749
- https://app.hubspot.com/api/external-options/v2/pagedFetch/0-1/OWNER?useIndexOffset=true&portalId=22152277&clienttimeout=14000&hs_static_app=settings-ui-users&hs_static_app_version=1.43001&limit=200&q=&offset=0&includeDeleted=true
- https://gist.github.com/0xDBJ/28072f7eea42571d5b4ebaabdcb21cce
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
Связанные уязвимости
CVSS3: 5.3
nvd
3 месяца назад
Incorrect access control in the REST API endpoint of HubSpot v1.29441 allows unauthenticated attackers to view users' data without proper authorization.