Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-827j-q3cq-7j37

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

admin_news.php in Archilles Newsworld up to 1.3.0 allows attackers to bypass authentication by obtaining the password hash for another user, for example through another Newsworld vulnerability, and specifying the hash in the pwd argument.

admin_news.php in Archilles Newsworld up to 1.3.0 allows attackers to bypass authentication by obtaining the password hash for another user, for example through another Newsworld vulnerability, and specifying the hash in the pwd argument.

EPSS

Процентиль: 75%
0.00856
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 9.8
nvd
больше 20 лет назад

admin_news.php in Archilles Newsworld up to 1.3.0 allows attackers to bypass authentication by obtaining the password hash for another user, for example through another Newsworld vulnerability, and specifying the hash in the pwd argument.

EPSS

Процентиль: 75%
0.00856
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-522