Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hf8m-4ppx-hx3q

Опубликовано: 01 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

Missing HTTPOnly flag in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an unauthenticated remote attacker to escalate privileges from unauthenticated to authenticated user via stealing and injecting the session- independent and static cookie UID.

Missing HTTPOnly flag in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an unauthenticated remote attacker to escalate privileges from unauthenticated to authenticated user via stealing and injecting the session- independent and static cookie UID.

EPSS

Процентиль: 68%
0.00569
Низкий

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 8.1
nvd
около 4 лет назад

Missing HTTPOnly flag in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an unauthenticated remote attacker to escalate privileges from unauthenticated to authenticated user via stealing and injecting the session- independent and static cookie UID.

EPSS

Процентиль: 68%
0.00569
Низкий

Дефекты

CWE-732