Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hjhx-mr4r-6j6j

Опубликовано: 04 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

This vulnerability exists in the Wave 2.0 due to missing authorization check on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter “user_id” through API request URLs which could lead to unauthorized creation, modification and deletion of alerts belonging to other user accounts.

This vulnerability exists in the Wave 2.0 due to missing authorization check on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter “user_id” through API request URLs which could lead to unauthorized creation, modification and deletion of alerts belonging to other user accounts.

EPSS

Процентиль: 60%
0.00394
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 6.5
nvd
больше 1 года назад

This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating API input parameters to gain unauthorized access and perform malicious activities on other user accounts.

EPSS

Процентиль: 60%
0.00394
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-639