Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ghjr-v93q-vx27

Опубликовано: 22 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

In Click Studios (SA) Pty Ltd Passwordstate 9435, users with access to a passwordlist can gain access to additional password lists without permissions. Specifically, an authenticated user who has write permissions to a password list in one folder (with the default permission model) can extend his permissions to all other password lists in the same folder.

In Click Studios (SA) Pty Ltd Passwordstate 9435, users with access to a passwordlist can gain access to additional password lists without permissions. Specifically, an authenticated user who has write permissions to a password list in one folder (with the default permission model) can extend his permissions to all other password lists in the same folder.

EPSS

Процентиль: 37%
0.00158
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 6.5
nvd
почти 4 года назад

In Click Studios (SA) Pty Ltd Passwordstate 9435, users with access to a passwordlist can gain access to additional password lists without permissions. Specifically, an authenticated user who has write permissions to a password list in one folder (with the default permission model) can extend his permissions to all other password lists in the same folder.

EPSS

Процентиль: 37%
0.00158
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-276