Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hrj6-9mp8-vxmq

Опубликовано: 11 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change user passwords by exploiting weak session management controls. Attackers can reuse IP-bound session identifiers to issue unauthorized requests to the userManager API and modify user credentials without proper authentication.

Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change user passwords by exploiting weak session management controls. Attackers can reuse IP-bound session identifiers to issue unauthorized requests to the userManager API and modify user credentials without proper authentication.

EPSS

Процентиль: 47%
0.00242
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-384

Связанные уязвимости

CVSS3: 6.5
nvd
около 2 месяцев назад

Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change user passwords by exploiting weak session management controls. Attackers can reuse IP-bound session identifiers to issue unauthorized requests to the userManager API and modify user credentials without proper authentication.

EPSS

Процентиль: 47%
0.00242
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-384