Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cxpg-8frp-cv2x

Опубликовано: 31 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The QOCA aim from Quanta Computer has an Authorization Bypass Through User-Controlled Key vulnerability. By controlling the user ID parameter, remote attackers with regular privileges could access certain features as any user, modify any user's account information and privileges, leading to privilege escalation.

The QOCA aim from Quanta Computer has an Authorization Bypass Through User-Controlled Key vulnerability. By controlling the user ID parameter, remote attackers with regular privileges could access certain features as any user, modify any user's account information and privileges, leading to privilege escalation.

EPSS

Процентиль: 46%
0.00237
Низкий

8.8 High

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 8.8
nvd
около 1 года назад

The QOCA aim from Quanta Computer has an Authorization Bypass Through User-Controlled Key vulnerability. By controlling the user ID parameter, remote attackers with regular privileges could access certain features as any user, modify any user's account information and privileges, leading to privilege escalation.

EPSS

Процентиль: 46%
0.00237
Низкий

8.8 High

CVSS3

Дефекты

CWE-639