Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gp56-58fv-r42c

Опубликовано: 14 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.

Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.

EPSS

Процентиль: 55%
0.00323
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 9.8
nvd
около 2 лет назад

Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.

EPSS

Процентиль: 55%
0.00323
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-276