Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-678w-qrpp-9pjw

Опубликовано: 21 мая 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs. The web application writes logs using a GET query string parameter. This parameter can be modified by an attacker, so that every action he performs is attributed to a different user. This can be exploited without authentication.

An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs. The web application writes logs using a GET query string parameter. This parameter can be modified by an attacker, so that every action he performs is attributed to a different user. This can be exploited without authentication.

EPSS

Процентиль: 40%
0.00184
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-117

Связанные уязвимости

CVSS3: 5.3
nvd
больше 1 года назад

An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs. The web application writes logs using a GET query string parameter. This parameter can be modified by an attacker, so that every action he performs is attributed to a different user. This can be exploited without authentication.

EPSS

Процентиль: 40%
0.00184
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-117