Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-768x-r5g5-79vc

Опубликовано: 18 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 8.8

Описание

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) trusts client-provided values for the 'epds_role_id' parameter without verification, allowing a remote, authenticated attacker to escalate their own privileges.

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) trusts client-provided values for the 'epds_role_id' parameter without verification, allowing a remote, authenticated attacker to escalate their own privileges.

EPSS

Процентиль: 51%
0.00724
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-602

Связанные уязвимости

CVSS3: 8.8
nvd
около 2 месяцев назад

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) trusts client-provided values for the 'epds_role_id' parameter without verification, allowing a remote, authenticated attacker to escalate their own privileges.

EPSS

Процентиль: 51%
0.00724
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-602