Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3v49-294p-4c7w

Опубликовано: 19 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The application is vulnerable to an unauthenticated parameter manipulation that allows an attacker to set the credentials to blank giving her access to the admin panel. Also vulnerable to account takeover and arbitrary password change.

The application is vulnerable to an unauthenticated parameter manipulation that allows an attacker to set the credentials to blank giving her access to the admin panel. Also vulnerable to account takeover and arbitrary password change.

EPSS

Процентиль: 27%
0.00098
Низкий

7.5 High

CVSS3

Дефекты

CWE-302

Связанные уязвимости

CVSS3: 7.5
nvd
почти 2 года назад

The application is vulnerable to an unauthenticated parameter manipulation that allows an attacker to set the credentials to blank giving her access to the admin panel. Also vulnerable to account takeover and arbitrary password change.

EPSS

Процентиль: 27%
0.00098
Низкий

7.5 High

CVSS3

Дефекты

CWE-302