Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4m3w-hp54-4622

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in Scytl sVote 2.1. Because the sdm-ws-rest API does not require authentication, an attacker can retrieve the administrative configuration by sending a POST request to the /sdm-ws-rest/preconfiguration URI.

An issue was discovered in Scytl sVote 2.1. Because the sdm-ws-rest API does not require authentication, an attacker can retrieve the administrative configuration by sending a POST request to the /sdm-ws-rest/preconfiguration URI.

EPSS

Процентиль: 47%
0.00238
Низкий

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 7.5
nvd
почти 5 лет назад

An issue was discovered in Scytl sVote 2.1. Because the sdm-ws-rest API does not require authentication, an attacker can retrieve the administrative configuration by sending a POST request to the /sdm-ws-rest/preconfiguration URI.

EPSS

Процентиль: 47%
0.00238
Низкий

Дефекты

CWE-306