Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4m72-xhqc-vmmg

Опубликовано: 24 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 8.3

Описание

sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without per-account access control. Attackers can invoke AccountController methods such as viewAction, editAction, deleteAction, and editPassAction without AccountFilterUser checks to modify or delete accounts beyond the scope of their assigned token permissions.

sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without per-account access control. Attackers can invoke AccountController methods such as viewAction, editAction, deleteAction, and editPassAction without AccountFilterUser checks to modify or delete accounts beyond the scope of their assigned token permissions.

EPSS

Процентиль: 13%
0.00223
Низкий

8.7 High

CVSS4

8.3 High

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 8.3
nvd
14 дней назад

sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without per-account access control. Attackers can invoke AccountController methods such as viewAction, editAction, deleteAction, and editPassAction without AccountFilterUser checks to modify or delete accounts beyond the scope of their assigned token permissions.

EPSS

Процентиль: 13%
0.00223
Низкий

8.7 High

CVSS4

8.3 High

CVSS3

Дефекты

CWE-639