Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q287-hpw8-q93x

Опубликовано: 05 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Bhima version 1.27.0 allows an attacker authenticated with normal user permissions to view sensitive data of other application users and data that should only be viewed by the administrator. This is possible because the application is vulnerable to IDOR, it does not properly validate user permissions with respect to certain actions the user can perform.

Bhima version 1.27.0 allows an attacker authenticated with normal user permissions to view sensitive data of other application users and data that should only be viewed by the administrator. This is possible because the application is vulnerable to IDOR, it does not properly validate user permissions with respect to certain actions the user can perform.

EPSS

Процентиль: 21%
0.00066
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 6.5
nvd
почти 3 года назад

Bhima version 1.27.0 allows an attacker authenticated with normal user permissions to view sensitive data of other application users and data that should only be viewed by the administrator. This is possible because the application is vulnerable to IDOR, it does not properly validate user permissions with respect to certain actions the user can perform.

EPSS

Процентиль: 21%
0.00066
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-639