Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hhf6-hx47-q457

Опубликовано: 10 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.3

Описание

An authentication bypass vulnerability was found in Videx's CyberAudit-Web. Through the exploitation of a logic flaw, an attacker could create a valid session without any credentials. This vulnerability has been patched in versions later than 9.5 and a patch has been made available to all instances of CyberAudit-Web, including the versions that are End of Maintenance (EOM). Anyone that requires support with the resolution of this issue can contact support@videx.com for assistance.

An authentication bypass vulnerability was found in Videx's CyberAudit-Web. Through the exploitation of a logic flaw, an attacker could create a valid session without any credentials. This vulnerability has been patched in versions later than 9.5 and a patch has been made available to all instances of CyberAudit-Web, including the versions that are End of Maintenance (EOM). Anyone that requires support with the resolution of this issue can contact support@videx.com for assistance.

EPSS

Процентиль: 55%
0.0032
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-287

Связанные уязвимости

nvd
10 месяцев назад

An authentication bypass vulnerability was found in Videx's CyberAudit-Web. Through the exploitation of a logic flaw, an attacker could create a valid session without any credentials. This vulnerability has been patched in versions later than 9.5 and a patch has been made available to all instances of CyberAudit-Web, including the versions that are End of Maintenance (EOM). Anyone that requires support with the resolution of this issue can contact support@videx.com for assistance.

EPSS

Процентиль: 55%
0.0032
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-287