Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jq7p-vh37-wmgw

Опубликовано: 28 авг. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Saho’s attendance devices ADM100 and ADM-100FP have a vulnerability of missing authentication for critical functions. An unauthenticated remote attacker can execute system commands in partial website URLs to read sensitive device information without permissions.

Saho’s attendance devices ADM100 and ADM-100FP have a vulnerability of missing authentication for critical functions. An unauthenticated remote attacker can execute system commands in partial website URLs to read sensitive device information without permissions.

EPSS

Процентиль: 33%
0.00129
Низкий

7.5 High

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 7.5
nvd
больше 2 лет назад

Saho’s attendance devices ADM100 and ADM-100FP have a vulnerability of missing authentication for critical functions. An unauthenticated remote attacker can execute system commands in partial website URLs to read sensitive device information without permissions.

EPSS

Процентиль: 33%
0.00129
Низкий

7.5 High

CVSS3

Дефекты

CWE-306