Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-px76-r7pq-gc82

Опубликовано: 22 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ARD. The flaw exists in the fe_uid parameter of the payment history API endpoint. An authenticated attacker can manipulate this parameter to access the payment history of other users without authorization.

An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ARD. The flaw exists in the fe_uid parameter of the payment history API endpoint. An authenticated attacker can manipulate this parameter to access the payment history of other users without authorization.

EPSS

Процентиль: 22%
0.00072
Низкий

7.5 High

CVSS3

Дефекты

CWE-693

Связанные уязвимости

CVSS3: 6.5
nvd
5 месяцев назад

An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ARD. The flaw exists in the `fe_uid` parameter of the payment history API endpoint. An authenticated attacker can manipulate this parameter to access the payment history of other users without authorization.

EPSS

Процентиль: 22%
0.00072
Низкий

7.5 High

CVSS3

Дефекты

CWE-693