Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7x7m-6347-w9xm

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or any sub-domain, via escalation of privileges. This issue affects all GateManager versions prior to 9.2c

An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or any sub-domain, via escalation of privileges. This issue affects all GateManager versions prior to 9.2c

EPSS

Процентиль: 44%
0.00216
Низкий

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 7.1
nvd
почти 5 лет назад

An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or any sub-domain, via escalation of privileges. This issue affects all GateManager versions prior to 9.2c

EPSS

Процентиль: 44%
0.00216
Низкий

Дефекты

CWE-269