Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-36w2-2wv6-x9j2

Опубликовано: 12 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Incorrect user role checking in multiple REST API endpoints in ProLion CryptoSpike 3.0.15P2 allows a remote attacker with low privileges to execute privileged functions and achieve privilege escalation via REST API endpoint invocation.

Incorrect user role checking in multiple REST API endpoints in ProLion CryptoSpike 3.0.15P2 allows a remote attacker with low privileges to execute privileged functions and achieve privilege escalation via REST API endpoint invocation.

EPSS

Процентиль: 56%
0.0034
Низкий

8.8 High

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 8.8
nvd
около 2 лет назад

Incorrect user role checking in multiple REST API endpoints in ProLion CryptoSpike 3.0.15P2 allows a remote attacker with low privileges to execute privileged functions and achieve privilege escalation via REST API endpoint invocation.

EPSS

Процентиль: 56%
0.0034
Низкий

8.8 High

CVSS3

Дефекты

CWE-863