Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4f5g-544m-849j

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The employee management page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the employee ID in specific parameters to arbitrary access employee's data, modify it, and then obtain administrator privilege and execute arbitrary command.

The employee management page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the employee ID in specific parameters to arbitrary access employee's data, modify it, and then obtain administrator privilege and execute arbitrary command.

EPSS

Процентиль: 68%
0.00566
Низкий

8.8 High

CVSS3

Дефекты

CWE-639
CWE-706

Связанные уязвимости

CVSS3: 8.8
nvd
больше 4 лет назад

The employee management page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the employee ID in specific parameters to arbitrary access employee's data, modify it, and then obtain administrator privilege and execute arbitrary command.

EPSS

Процентиль: 68%
0.00566
Низкий

8.8 High

CVSS3

Дефекты

CWE-639
CWE-706