Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-477f-m8hc-8q86

Опубликовано: 28 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to access arbitrary files uploaded by any user.

The eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to access arbitrary files uploaded by any user.

EPSS

Процентиль: 38%
0.00168
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 5.3
nvd
больше 1 года назад

The eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to access arbitrary files uploaded by any user.

EPSS

Процентиль: 38%
0.00168
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-639