Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7gc2-q47v-36w5

Опубликовано: 01 мар. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the action name parameter to ExportEmployeeDetails.aspx, and to ExportReportingManager.aspx.

An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the action name parameter to ExportEmployeeDetails.aspx, and to ExportReportingManager.aspx.

EPSS

Процентиль: 100%
0.92526
Критический

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
почти 3 года назад

An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the action name parameter to ExportEmployeeDetails.aspx, and to ExportReportingManager.aspx.

EPSS

Процентиль: 100%
0.92526
Критический

7.5 High

CVSS3