Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fpr5-99x5-v6hh

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Learnsite 1.2.5.0 contains a remote privilege escalation vulnerability in /Manager/index.aspx through the JudgIsAdmin() function. By modifying the initial letter of the key of a user cookie, the key of the administrator cookie can be obtained.

Learnsite 1.2.5.0 contains a remote privilege escalation vulnerability in /Manager/index.aspx through the JudgIsAdmin() function. By modifying the initial letter of the key of a user cookie, the key of the administrator cookie can be obtained.

EPSS

Процентиль: 67%
0.00548
Низкий

8.8 High

CVSS3

Дефекты

CWE-269
CWE-287

Связанные уязвимости

CVSS3: 8.8
nvd
почти 5 лет назад

Learnsite 1.2.5.0 contains a remote privilege escalation vulnerability in /Manager/index.aspx through the JudgIsAdmin() function. By modifying the initial letter of the key of a user cookie, the key of the administrator cookie can be obtained.

EPSS

Процентиль: 67%
0.00548
Низкий

8.8 High

CVSS3

Дефекты

CWE-269
CWE-287