Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-734x-3wjx-2xxp

Опубликовано: 13 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

A vulnerability classified as problematic has been found in Huaxia ERP up to 3.1. Affected is an unknown function of the file src/main/java/com/jsh/erp/controller/UserController.java. The manipulation leads to weak password recovery. It is possible to launch the attack remotely. Upgrading to version 3.2 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-250596.

A vulnerability classified as problematic has been found in Huaxia ERP up to 3.1. Affected is an unknown function of the file src/main/java/com/jsh/erp/controller/UserController.java. The manipulation leads to weak password recovery. It is possible to launch the attack remotely. Upgrading to version 3.2 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-250596.

EPSS

Процентиль: 16%
0.00052
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-640

Связанные уязвимости

CVSS3: 5.3
nvd
около 2 лет назад

A vulnerability classified as problematic has been found in Huaxia ERP up to 3.1. Affected is an unknown function of the file src/main/java/com/jsh/erp/controller/UserController.java. The manipulation leads to weak password recovery. It is possible to launch the attack remotely. Upgrading to version 3.2 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-250596.

EPSS

Процентиль: 16%
0.00052
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-640