Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hr2v-vc99-3c32

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by XML External Entity (XXE) injection. An authenticated attacker can compromise the private keys of a JWT token and reuse them to manipulate the access tokens to access the platform as any desired user (clients and administrators).

Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by XML External Entity (XXE) injection. An authenticated attacker can compromise the private keys of a JWT token and reuse them to manipulate the access tokens to access the platform as any desired user (clients and administrators).

EPSS

Процентиль: 68%
0.0056
Низкий

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 6.5
nvd
почти 5 лет назад

Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by XML External Entity (XXE) injection. An authenticated attacker can compromise the private keys of a JWT token and reuse them to manipulate the access tokens to access the platform as any desired user (clients and administrators).

EPSS

Процентиль: 68%
0.0056
Низкий

Дефекты

CWE-611