Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mmg7-3c66-c28q

Опубликовано: 01 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.6

Описание

Incorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurvey allows any logged-in user to obtain the private information of any other user.

Critical information retrieved:

  • APIKEY (1 year user Session)
  • RefreshToken (10 minutes user Session)
  • Password hashed with bcrypt
  • User IP
  • Email
  • Full Name

Incorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurvey allows any logged-in user to obtain the private information of any other user.

Critical information retrieved:

  • APIKEY (1 year user Session)
  • RefreshToken (10 minutes user Session)
  • Password hashed with bcrypt
  • User IP
  • Email
  • Full Name

EPSS

Процентиль: 15%
0.0005
Низкий

8.6 High

CVSS4

Дефекты

CWE-863

Связанные уязвимости

nvd
2 месяца назад

Incorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurvey allows any logged-in user to obtain the private information of any other user. Critical information retrieved: * APIKEY (1 year user Session) * RefreshToken (10 minutes user Session) * Password hashed with bcrypt * User IP * Email * Full Name

EPSS

Процентиль: 15%
0.0005
Низкий

8.6 High

CVSS4

Дефекты

CWE-863