Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cm7f-83pq-pfp3

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Stratodesk NoTouch Center before 4.4.68 is affected by: Incorrect Access Control. A low privileged user on the platform, for example a user with "helpdesk" privileges, can perform privileged operations including adding a new administrator to the platform via the easyadmin/user/submitCreateTCUser.do page.

Stratodesk NoTouch Center before 4.4.68 is affected by: Incorrect Access Control. A low privileged user on the platform, for example a user with "helpdesk" privileges, can perform privileged operations including adding a new administrator to the platform via the easyadmin/user/submitCreateTCUser.do page.

EPSS

Процентиль: 52%
0.00295
Низкий

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 8.8
nvd
около 5 лет назад

Stratodesk NoTouch Center before 4.4.68 is affected by: Incorrect Access Control. A low privileged user on the platform, for example a user with "helpdesk" privileges, can perform privileged operations including adding a new administrator to the platform via the easyadmin/user/submitCreateTCUser.do page.

EPSS

Процентиль: 52%
0.00295
Низкий

Дефекты

CWE-269