Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3j4c-6c9j-p6jj

Опубликовано: 13 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

Insecure direct object reference (IDOR) vulnerability in Anapi Group's h6web, allows an authenticated attacker to access other users' information by making a POST request and modifying the “pkrelated” parameter in the “/h6web/ha_datos_hermano.php” endpoint to refer to another user. In addition, the first request could also allow the attacker to impersonate other users. As a result, all requests made after exploitation of the IDOR vulnerability will be executed with the privileges of the impersonated user.

Insecure direct object reference (IDOR) vulnerability in Anapi Group's h6web, allows an authenticated attacker to access other users' information by making a POST request and modifying the “pkrelated” parameter in the “/h6web/ha_datos_hermano.php” endpoint to refer to another user. In addition, the first request could also allow the attacker to impersonate other users. As a result, all requests made after exploitation of the IDOR vulnerability will be executed with the privileges of the impersonated user.

EPSS

Процентиль: 29%
0.00108
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 9.1
nvd
12 месяцев назад

Insecure direct object reference (IDOR) vulnerability in Anapi Group's h6web, allows an authenticated attacker to access other users' information by making a POST request and modifying the “pkrelated” parameter in the “/h6web/ha_datos_hermano.php” endpoint to refer to another user. In addition, the first request could also allow the attacker to impersonate other users. As a result, all requests made after exploitation of the IDOR vulnerability will be executed with the privileges of the impersonated user.

EPSS

Процентиль: 29%
0.00108
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-639