Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3qwj-cx3m-c3pj

Опубликовано: 15 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

SmartStar Software CWS is a web-based integration platform, it has a vulnerability of missing authorization and users are able to access data or perform actions that they should not be allowed to perform via commands. An authenticated with normal user privilege can execute administrator privilege, resulting in performing arbitrary system operations or disrupting service.

SmartStar Software CWS is a web-based integration platform, it has a vulnerability of missing authorization and users are able to access data or perform actions that they should not be allowed to perform via commands. An authenticated with normal user privilege can execute administrator privilege, resulting in performing arbitrary system operations or disrupting service.

EPSS

Процентиль: 36%
0.00152
Низкий

8.8 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 8.8
nvd
около 2 лет назад

SmartStar Software CWS is a web-based integration platform, it has a vulnerability of missing authorization and users are able to access data or perform actions that they should not be allowed to perform via commands. An authenticated with normal user privilege can execute administrator privilege, resulting in performing arbitrary system operations or disrupting service.

EPSS

Процентиль: 36%
0.00152
Низкий

8.8 High

CVSS3

Дефекты

CWE-862