Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7fc5-p6pg-8vrj

Опубликовано: 07 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

A flaw was found in the 3scale developer portal. This issue can allow account creation or updates passed through hidden or read-only fields, the contents of which may be altered. This flaw allows an attacker to access or modify restricted information.

A flaw was found in the 3scale developer portal. This issue can allow account creation or updates passed through hidden or read-only fields, the contents of which may be altered. This flaw allows an attacker to access or modify restricted information.

EPSS

Процентиль: 13%
0.00042
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-281

Связанные уязвимости

CVSS3: 7.5
nvd
3 месяца назад

A flaw was found in the 3scale Developer Portal. When creating or updating an account in the Developer Portal UI it is possible to modify fields explicitly configured as read-only or hidden, allowing an attacker to modify restricted information.

EPSS

Процентиль: 13%
0.00042
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-281