Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6h2q-7gh7-pc6c

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Plunet BusinessManager 4.1 and earlier allows remote authenticated users to bypass access restrictions and (1) read sensitive Customer or Order data via a modified Pfad parameter to pagesUTF8/Sys_DirAnzeige.jsp, or (2) list sensitive Jobs via a direct request to pagesUTF8/auftrag_job.jsp.

Plunet BusinessManager 4.1 and earlier allows remote authenticated users to bypass access restrictions and (1) read sensitive Customer or Order data via a modified Pfad parameter to pagesUTF8/Sys_DirAnzeige.jsp, or (2) list sensitive Jobs via a direct request to pagesUTF8/auftrag_job.jsp.

EPSS

Процентиль: 88%
0.03971
Низкий

Связанные уязвимости

nvd
почти 17 лет назад

Plunet BusinessManager 4.1 and earlier allows remote authenticated users to bypass access restrictions and (1) read sensitive Customer or Order data via a modified Pfad parameter to pagesUTF8/Sys_DirAnzeige.jsp, or (2) list sensitive Jobs via a direct request to pagesUTF8/auftrag_job.jsp.

EPSS

Процентиль: 88%
0.03971
Низкий