Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-938p-268q-56rj

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation. This issue has been fixed in 3.9.7.

lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation. This issue has been fixed in 3.9.7.

EPSS

Процентиль: 100%
0.92196
Критический

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.8
nvd
около 5 лет назад

lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation. This issue has been fixed in 3.9.7.

EPSS

Процентиль: 100%
0.92196
Критический

Дефекты

CWE-287