Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-737f-w9fg-hw85

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

MoveSortedContentAction in C1 Financial Services Contelligent 9.1.4 does not check "the additional environment security configuration," which allows remote attackers with write permissions to reorder components.

MoveSortedContentAction in C1 Financial Services Contelligent 9.1.4 does not check "the additional environment security configuration," which allows remote attackers with write permissions to reorder components.

EPSS

Процентиль: 73%
0.00785
Низкий

Дефекты

CWE-362

Связанные уязвимости

nvd
почти 19 лет назад

MoveSortedContentAction in C1 Financial Services Contelligent 9.1.4 does not check "the additional environment security configuration," which allows remote attackers with write permissions to reorder components.

EPSS

Процентиль: 73%
0.00785
Низкий

Дефекты

CWE-362