Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-69q6-gh68-57p3

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can allow for manipulation and takeover of user accounts if successfully exploited. The following vulnerable functions are exposed: ChangePassword, SaveUserProfile, and GetUser.

Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can allow for manipulation and takeover of user accounts if successfully exploited. The following vulnerable functions are exposed: ChangePassword, SaveUserProfile, and GetUser.

EPSS

Процентиль: 93%
0.118
Средний

9.8 Critical

CVSS3

Дефекты

CWE-862
CWE-863

Связанные уязвимости

CVSS3: 9.8
nvd
больше 5 лет назад

Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can allow for manipulation and takeover of user accounts if successfully exploited. The following vulnerable functions are exposed: ChangePassword, SaveUserProfile, and GetUser.

EPSS

Процентиль: 93%
0.118
Средний

9.8 Critical

CVSS3

Дефекты

CWE-862
CWE-863