Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hg2f-jm3j-qjq8

Опубликовано: 06 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 9.8

Описание

Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization controls. Attackers can access hidden system resources like '/#/content-creation' by manipulating client-side access restrictions.

Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization controls. Attackers can access hidden system resources like '/#/content-creation' by manipulating client-side access restrictions.

EPSS

Процентиль: 29%
0.00105
Низкий

6.9 Medium

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 9.8
nvd
около 1 месяца назад

Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization controls. Attackers can access hidden system resources like '/#/content-creation' by manipulating client-side access restrictions.

EPSS

Процентиль: 29%
0.00105
Низкий

6.9 Medium

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-639