Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3grp-7h7h-xcr6

Опубликовано: 19 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.4

Описание

Authorization Bypass Through User-Controlled Key, CWE - 862 - Missing Authorization, – Improper Authorization vulnerability in Bimser Solution Software Trade Inc. EBA Document and Workflow Management System allows – Exploitation of Trusted Identifiers, – Exploitation of Authorization, – Variable Manipulation.This issue affects eBA Document and Workflow Management System: from 6.7.164 before 6.7.166.

Authorization Bypass Through User-Controlled Key, CWE - 862 - Missing Authorization, – Improper Authorization vulnerability in Bimser Solution Software Trade Inc. EBA Document and Workflow Management System allows – Exploitation of Trusted Identifiers, – Exploitation of Authorization, – Variable Manipulation.This issue affects eBA Document and Workflow Management System: from 6.7.164 before 6.7.166.

EPSS

Процентиль: 4%
0.0002
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 6.4
nvd
5 месяцев назад

Authorization Bypass Through User-Controlled Key, Improper Authorization vulnerability in Bimser Solution Software Trade Inc. EBA Document and Workflow Management System allows Forceful Browsing.This issue affects eBA Document and Workflow Management System: from 6.7.164 before 6.7.166.

EPSS

Процентиль: 4%
0.0002
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-285