Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9fhw-hf7x-9gjc

Опубликовано: 09 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Canon Medical Informatics Vitrea Vision 7.7.76.1 does not adequately enforce access controls. An authenticated user is able to gain unauthorized access to imaging records by tampering with the vitrea-view/studies/search patientId parameter.

Canon Medical Informatics Vitrea Vision 7.7.76.1 does not adequately enforce access controls. An authenticated user is able to gain unauthorized access to imaging records by tampering with the vitrea-view/studies/search patientId parameter.

EPSS

Процентиль: 54%
0.00318
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 6.5
nvd
около 3 лет назад

Canon Medical Informatics Vitrea Vision 7.7.76.1 does not adequately enforce access controls. An authenticated user is able to gain unauthorized access to imaging records by tampering with the vitrea-view/studies/search patientId parameter.

EPSS

Процентиль: 54%
0.00318
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-639