Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pr8c-fv23-2j59

Опубликовано: 01 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control via the logout function. After a user logs out, their token is still available and fetches information in the logged-in state.

macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control via the logout function. After a user logs out, their token is still available and fetches information in the logged-in state.

EPSS

Процентиль: 38%
0.00164
Низкий

7.5 High

CVSS3

Дефекты

CWE-284
CWE-863

Связанные уязвимости

CVSS3: 7.5
nvd
около 1 года назад

macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control via the logout function. After a user logs out, their token is still available and fetches information in the logged-in state.

EPSS

Процентиль: 38%
0.00164
Низкий

7.5 High

CVSS3

Дефекты

CWE-284
CWE-863