Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fp4f-m8g2-6548

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). The webserver could allow unauthorized actions via special urls for unpriviledged users. The settings of the UMC authorization server could be changed to add a rogue server by an attacker authenticating with unprivilege user rights.

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). The webserver could allow unauthorized actions via special urls for unpriviledged users. The settings of the UMC authorization server could be changed to add a rogue server by an attacker authenticating with unprivilege user rights.

EPSS

Процентиль: 56%
0.00336
Низкий

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 8.8
nvd
почти 5 лет назад

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). The webserver could allow unauthorized actions via special urls for unpriviledged users. The settings of the UMC authorization server could be changed to add a rogue server by an attacker authenticating with unprivilege user rights.

EPSS

Процентиль: 56%
0.00336
Низкий

Дефекты

CWE-863