Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-989f-fh5x-8jw4

Опубликовано: 31 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 5.3

Описание

OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows an unauthenticated, remote attacker to query the /App/CreateRequest.aspx endpoint to check for the existence of valid usernames. There are no rate-limiting mechanisms in place.

OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows an unauthenticated, remote attacker to query the /App/CreateRequest.aspx endpoint to check for the existence of valid usernames. There are no rate-limiting mechanisms in place.

EPSS

Процентиль: 10%
0.00035
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-204

Связанные уязвимости

CVSS3: 5.3
nvd
6 месяцев назад

OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows an unauthenticated, remote attacker to query the /App/CreateRequest.aspx endpoint to check for the existence of valid usernames. There are no rate-limiting mechanisms in place.

EPSS

Процентиль: 10%
0.00035
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-204