Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f423-79c7-g4mq

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

The employee management page of Flygo contains an Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attacker can manipulate the user data and then over-write another employee’s user data by specifying that employee’s ID in the API parameter.

The employee management page of Flygo contains an Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attacker can manipulate the user data and then over-write another employee’s user data by specifying that employee’s ID in the API parameter.

EPSS

Процентиль: 30%
0.00113
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-639
CWE-706

Связанные уязвимости

CVSS3: 4.3
nvd
больше 4 лет назад

The employee management page of Flygo contains an Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attacker can manipulate the user data and then over-write another employee’s user data by specifying that employee’s ID in the API parameter.

EPSS

Процентиль: 30%
0.00113
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-639
CWE-706