Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m95m-2xc3-p525

Опубликовано: 01 дек. 2021
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

Incorrect Access Control in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an authenticated remote attacker to view the Shape Editor and Settings, which are functionality for higher privileged users, via identifying said components in the front-end source code or other means.

Incorrect Access Control in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an authenticated remote attacker to view the Shape Editor and Settings, which are functionality for higher privileged users, via identifying said components in the front-end source code or other means.

EPSS

Процентиль: 33%
0.00128
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-668

Связанные уязвимости

CVSS3: 4.3
nvd
около 4 лет назад

Incorrect Access Control in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an authenticated remote attacker to view the Shape Editor and Settings, which are functionality for higher privileged users, via identifying said components in the front-end source code or other means.

EPSS

Процентиль: 33%
0.00128
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-668