Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f6h7-jxqx-887x

Опубликовано: 05 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due to insufficient permission validation and excessive data exposure in the backend, an authenticated user with basic read permissions can retrieve sensitive information for all platform users.

Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due to insufficient permission validation and excessive data exposure in the backend, an authenticated user with basic read permissions can retrieve sensitive information for all platform users.

EPSS

Процентиль: 8%
0.0003
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 6.5
nvd
2 месяца назад

Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due to insufficient permission validation and excessive data exposure in the backend, an authenticated user with basic read permissions can retrieve sensitive information for all platform users.

EPSS

Процентиль: 8%
0.0003
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863