Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9fg6-4jc3-m2x8

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

newbee-mall all versions are affected by incorrect access control to remotely gain privileges through NewBeeMallIndexConfigServiceImpl.java. Unauthorized changes can be made to any user information through the userID.

newbee-mall all versions are affected by incorrect access control to remotely gain privileges through NewBeeMallIndexConfigServiceImpl.java. Unauthorized changes can be made to any user information through the userID.

EPSS

Процентиль: 43%
0.00206
Низкий

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 7.5
nvd
около 5 лет назад

newbee-mall all versions are affected by incorrect access control to remotely gain privileges through NewBeeMallIndexConfigServiceImpl.java. Unauthorized changes can be made to any user information through the userID.

EPSS

Процентиль: 43%
0.00206
Низкий

Дефекты

CWE-863