Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-44vh-88m4-ph9w

Опубликовано: 14 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7.4

Описание

This vulnerability exists in RupeeWeb trading platform due to insufficient authorization controls on certain API endpoints handling addition and deletion operations. Successful exploitation of this vulnerability could allow an authenticated remote attacker to modify information belonging to other user accounts.

This vulnerability exists in RupeeWeb trading platform due to insufficient authorization controls on certain API endpoints handling addition and deletion operations. Successful exploitation of this vulnerability could allow an authenticated remote attacker to modify information belonging to other user accounts.

EPSS

Процентиль: 38%
0.00461
Низкий

7.4 High

CVSS4

Дефекты

CWE-266

Связанные уязвимости

nvd
больше 1 года назад

This vulnerability exists in RupeeWeb trading platform due to insufficient authorization controls on certain API endpoints handling addition and deletion operations. Successful exploitation of this vulnerability could allow an authenticated remote attacker to modify information belonging to other user accounts.

EPSS

Процентиль: 38%
0.00461
Низкий

7.4 High

CVSS4

Дефекты

CWE-266