Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hpgr-7w89-8xm5

Опубликовано: 07 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

Squiz Matrix CMS 6.20 is vulnerable to an Insecure Direct Object Reference caused by failure to correctly validate authorization when submitting a request to change a user's contact details.

Squiz Matrix CMS 6.20 is vulnerable to an Insecure Direct Object Reference caused by failure to correctly validate authorization when submitting a request to change a user's contact details.

EPSS

Процентиль: 53%
0.00297
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 5.3
nvd
больше 3 лет назад

Squiz Matrix CMS 6.20 is vulnerable to an Insecure Direct Object Reference caused by failure to correctly validate authorization when submitting a request to change a user's contact details. NOTE: this is disputed by both the vendor and the original discoverer because it is a site-specific finding, not a finding about the Squiz Matrix CMS product.

EPSS

Процентиль: 53%
0.00297
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-639