Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4f45-vh57-p56g

Опубликовано: 14 авг. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the username, allowing an attacker to login into the application with the default user "cyberpower" by appending a non-printable character.An unauthenticated attacker can leverage this vulnerability to log in to the CypberPower PowerPanel Enterprise as an administrator with hardcoded default credentials.

An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the username, allowing an attacker to login into the application with the default user "cyberpower" by appending a non-printable character.An unauthenticated attacker can leverage this vulnerability to log in to the CypberPower PowerPanel Enterprise as an administrator with hardcoded default credentials.

EPSS

Процентиль: 42%
0.00195
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-150

Связанные уязвимости

CVSS3: 9.8
nvd
больше 2 лет назад

An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the username, allowing an attacker to login into the application with the default user "cyberpower" by appending a non-printable character.An unauthenticated attacker can leverage this vulnerability to log in to the CypberPower PowerPanel Enterprise as an administrator with hardcoded default credentials.

EPSS

Процентиль: 42%
0.00195
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-150