Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j5jq-5w3c-xc48

Опубликовано: 13 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

vinny/views.py: (ModifyEmailNotifications) IDOR: view fetches VinceCommEmail by raw pk from URL and toggles email_function/name without checking the record's contact belongs to the requesting group-admin. Lets a vendor admin flip notification routing (or read email/name) for another vendor's contact.

vinny/views.py: (ModifyEmailNotifications) IDOR: view fetches VinceCommEmail by raw pk from URL and toggles email_function/name without checking the record's contact belongs to the requesting group-admin. Lets a vendor admin flip notification routing (or read email/name) for another vendor's contact.

EPSS

Процентиль: 15%
0.00237
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 5.3
nvd
28 дней назад

vinny/views.py: (ModifyEmailNotifications) IDOR: view fetches VinceCommEmail by raw pk from URL and toggles email_function/name without checking the record's contact belongs to the requesting group-admin. Lets a vendor admin flip notification routing (or read email/name) for another vendor's contact.

EPSS

Процентиль: 15%
0.00237
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-639