Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5ffr-q63g-qhpp

Опубликовано: 25 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Planet eStream before 6.72.10.07 allows a low-privileged user to gain access to administrative and high-privileged user accounts by changing the value of the ON cookie. A brute-force attack can calculate a value that provides permanent access.

Planet eStream before 6.72.10.07 allows a low-privileged user to gain access to administrative and high-privileged user accounts by changing the value of the ON cookie. A brute-force attack can calculate a value that provides permanent access.

EPSS

Процентиль: 54%
0.00318
Низкий

8.8 High

CVSS3

Дефекты

CWE-307

Связанные уязвимости

CVSS3: 8.8
nvd
около 3 лет назад

Planet eStream before 6.72.10.07 allows a low-privileged user to gain access to administrative and high-privileged user accounts by changing the value of the ON cookie. A brute-force attack can calculate a value that provides permanent access.

EPSS

Процентиль: 54%
0.00318
Низкий

8.8 High

CVSS3

Дефекты

CWE-307