Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-65x3-jm69-w8w4

Опубликовано: 31 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.3

Описание

Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 suffers from insufficient server-side authorization. Authenticated attackers can call several endpoints and perform create/update/delete actions on resources owned by arbitrary users by manipulating request parameters (e.g., owner or resource id).

Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 suffers from insufficient server-side authorization. Authenticated attackers can call several endpoints and perform create/update/delete actions on resources owned by arbitrary users by manipulating request parameters (e.g., owner or resource id).

EPSS

Процентиль: 16%
0.00051
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 6.3
nvd
3 месяца назад

Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 suffers from insufficient server-side authorization. Authenticated attackers can call several endpoints and perform create/update/delete actions on resources owned by arbitrary users by manipulating request parameters (e.g., owner or resource id).

EPSS

Процентиль: 16%
0.00051
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-284