Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8fh2-hm78-4frg

Опубликовано: 22 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 6.3

Описание

A vulnerability was detected in mickasmt next-saas-stripe-starter 1.0.0. Affected by this vulnerability is the function updateUserrole of the file actions/update-user-role.ts. The manipulation of the argument userId/role results in improper authorization. The attack may be launched remotely.

A vulnerability was detected in mickasmt next-saas-stripe-starter 1.0.0. Affected by this vulnerability is the function updateUserrole of the file actions/update-user-role.ts. The manipulation of the argument userId/role results in improper authorization. The attack may be launched remotely.

EPSS

Процентиль: 10%
0.00035
Низкий

5.3 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-266

Связанные уязвимости

CVSS3: 6.3
nvd
18 дней назад

A vulnerability was detected in mickasmt next-saas-stripe-starter 1.0.0. Affected by this vulnerability is the function updateUserrole of the file actions/update-user-role.ts. The manipulation of the argument userId/role results in improper authorization. The attack may be launched remotely.

EPSS

Процентиль: 10%
0.00035
Низкий

5.3 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-266