Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-84cx-5p9q-mqrm

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Harris Ormed Self Service before 2019.1.4 allows an authenticated user to view W-2 forms belonging to other users via an arbitrary empNo value to the ORMEDMIS/Data/PY/T4W2Service.svc/RetrieveW2EntriesForEmployee URI, thus exposing sensitive information including employee tax information, social security numbers, home addresses, and more.

Harris Ormed Self Service before 2019.1.4 allows an authenticated user to view W-2 forms belonging to other users via an arbitrary empNo value to the ORMEDMIS/Data/PY/T4W2Service.svc/RetrieveW2EntriesForEmployee URI, thus exposing sensitive information including employee tax information, social security numbers, home addresses, and more.

EPSS

Процентиль: 57%
0.0035
Низкий

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.3
nvd
почти 6 лет назад

Harris Ormed Self Service before 2019.1.4 allows an authenticated user to view W-2 forms belonging to other users via an arbitrary empNo value to the ORMEDMIS/Data/PY/T4W2Service.svc/RetrieveW2EntriesForEmployee URI, thus exposing sensitive information including employee tax information, social security numbers, home addresses, and more.

EPSS

Процентиль: 57%
0.0035
Низкий

Дефекты

CWE-200