Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m4jr-5r4g-w2vh

Опубликовано: 10 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.3

Описание

Direct Object Reference Vulnerability (IDOR) in i2A's CronosWeb, in versions prior to 25.00.00.12, inclusive. This vulnerability could allow an authenticated attacker to access other users' documents by manipulating the ‘documentCode’ parameter in '/CronosWeb/Modulos/Personas/DocumentosPersonales/AdjuntarDocumentosPersonas'.

Direct Object Reference Vulnerability (IDOR) in i2A's CronosWeb, in versions prior to 25.00.00.12, inclusive. This vulnerability could allow an authenticated attacker to access other users' documents by manipulating the ‘documentCode’ parameter in '/CronosWeb/Modulos/Personas/DocumentosPersonales/AdjuntarDocumentosPersonas'.

EPSS

Процентиль: 15%
0.0005
Низкий

8.3 High

CVSS4

Дефекты

CWE-639

Связанные уязвимости

nvd
2 месяца назад

Direct Object Reference Vulnerability (IDOR) in i2A's CronosWeb, in versions prior to 25.00.00.12, inclusive. This vulnerability could allow an authenticated attacker to access other users' documents by manipulating the ‘documentCode’ parameter in '/CronosWeb/Modulos/Personas/DocumentosPersonales/AdjuntarDocumentosPersonas'.

EPSS

Процентиль: 15%
0.0005
Низкий

8.3 High

CVSS4

Дефекты

CWE-639