Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8r96-j25h-hj4g

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

The check-in record page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the employee ID and date in specific parameters to access particular employee’s check-in record.

The check-in record page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the employee ID and date in specific parameters to access particular employee’s check-in record.

EPSS

Процентиль: 30%
0.00111
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-639
CWE-706

Связанные уязвимости

CVSS3: 4.3
nvd
больше 4 лет назад

The check-in record page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the employee ID and date in specific parameters to access particular employee’s check-in record.

EPSS

Процентиль: 30%
0.00111
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-639
CWE-706