Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hqfm-f44v-gmx6

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

The bulletin function of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the bulletin ID in specific Url parameters and access and modify bulletin particular content.

The bulletin function of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the bulletin ID in specific Url parameters and access and modify bulletin particular content.

EPSS

Процентиль: 29%
0.00108
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-639
CWE-706

Связанные уязвимости

CVSS3: 5.4
nvd
больше 4 лет назад

The bulletin function of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the bulletin ID in specific Url parameters and access and modify bulletin particular content.

EPSS

Процентиль: 29%
0.00108
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-639
CWE-706