Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5f5h-xp93-w647

Опубликовано: 04 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 6.5

Описание

Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains a broken access control vulnerability that allows authenticated users to access other users' pet data by exploiting missing ownership verification. Attackers can send requests to /member/pet/detailV2 with arbitrary pet IDs to retrieve sensitive information including pet details, member IDs, and avatar URLs without proper authorization checks.

Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains a broken access control vulnerability that allows authenticated users to access other users' pet data by exploiting missing ownership verification. Attackers can send requests to /member/pet/detailV2 with arbitrary pet IDs to retrieve sensitive information including pet details, member IDs, and avatar URLs without proper authorization checks.

EPSS

Процентиль: 10%
0.00035
Низкий

6.9 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-612

Связанные уязвимости

CVSS3: 6.5
nvd
около 1 месяца назад

Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains a broken access control vulnerability that allows authenticated users to access other users' pet data by exploiting missing ownership verification. Attackers can send requests to /member/pet/detailV2 with arbitrary pet IDs to retrieve sensitive information including pet details, member IDs, and avatar URLs without proper authorization checks.

EPSS

Процентиль: 10%
0.00035
Низкий

6.9 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-612