Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-439v-7mv7-5p44

Опубликовано: 12 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.4
CVSS3: 6.3

Описание

Inductive Automation Ignition Software is vulnerable to an unauthenticated API endpoint exposure that may allow an attacker to remotely change the "forgot password" recovery email address.

Inductive Automation Ignition Software is vulnerable to an unauthenticated API endpoint exposure that may allow an attacker to remotely change the "forgot password" recovery email address.

EPSS

Процентиль: 28%
0.00345
Низкий

5.4 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 6.3
nvd
6 месяцев назад

A privileged Ignition user, intentionally or otherwise, imports an external file with a specially crafted payload, which executes embedded malicious code.

EPSS

Процентиль: 28%
0.00345
Низкий

5.4 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-502