Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f93h-pcqv-5rf7

Опубликовано: 25 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and password, via a crafted POST request sent to the endpoint /User/ChangeUser/s in the ChangeUser function in UserController.java

An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and password, via a crafted POST request sent to the endpoint /User/ChangeUser/s in the ChangeUser function in UserController.java

EPSS

Процентиль: 17%
0.00056
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 1 года назад

An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and password, via a crafted POST request sent to the endpoint /User/ChangeUser/s in the ChangeUser function in UserController.java

EPSS

Процентиль: 17%
0.00056
Низкий

7.5 High

CVSS3