Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-78xf-28c3-3286

Опубликовано: 05 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

A vulnerability has been found in Facepay 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /face-recognition-php/facepay-master/camera.php. The manipulation of the argument userId leads to authorization bypass. The attack can be launched remotely. The identifier VDB-214789 was assigned to this vulnerability.

A vulnerability has been found in Facepay 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /face-recognition-php/facepay-master/camera.php. The manipulation of the argument userId leads to authorization bypass. The attack can be launched remotely. The identifier VDB-214789 was assigned to this vulnerability.

EPSS

Процентиль: 33%
0.00129
Низкий

8.8 High

CVSS3

Дефекты

CWE-266
CWE-269
CWE-285

Связанные уязвимости

CVSS3: 6.3
nvd
около 3 лет назад

A vulnerability has been found in Facepay 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /face-recognition-php/facepay-master/camera.php. The manipulation of the argument userId leads to authorization bypass. The attack can be launched remotely. The identifier VDB-214789 was assigned to this vulnerability.

EPSS

Процентиль: 33%
0.00129
Низкий

8.8 High

CVSS3

Дефекты

CWE-266
CWE-269
CWE-285