Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g5hj-6p24-45c3

Опубликовано: 09 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Canlineapp Online 1.1 is vulnerable to Broken Access Control and allows users with the Auditor role to create an audit template as a result of improper authorization checks. This feature is designated for supervisor role, but auditors have been able to successfully create audit templates from their account.

Canlineapp Online 1.1 is vulnerable to Broken Access Control and allows users with the Auditor role to create an audit template as a result of improper authorization checks. This feature is designated for supervisor role, but auditors have been able to successfully create audit templates from their account.

EPSS

Процентиль: 32%
0.00121
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 6.5
nvd
около 1 года назад

Canlineapp Online 1.1 is vulnerable to Broken Access Control and allows users with the Auditor role to create an audit template as a result of improper authorization checks. This feature is designated for supervisor role, but auditors have been able to successfully create audit templates from their account.

EPSS

Процентиль: 32%
0.00121
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863