Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-78rc-hmp8-p646

Опубликовано: 09 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Report Browse section of Log & Report may allow an unauthorized and unauthenticated user to access the Log reports via their URLs.

An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Report Browse section of Log & Report may allow an unauthorized and unauthenticated user to access the Log reports via their URLs.

EPSS

Процентиль: 65%
0.00489
Низкий

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 5.3
nvd
около 4 лет назад

An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Report Browse section of Log & Report may allow an unauthorized and unauthenticated user to access the Log reports via their URLs.

EPSS

Процентиль: 65%
0.00489
Низкий

Дефекты

CWE-863