Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q2wq-f7jq-885v

Опубликовано: 21 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.1
CVSS3: 6.5

Описание

Sricam DeviceViewer 3.12.0.1 contains a password change security bypass vulnerability that allows authenticated users to change passwords without proper validation of the old password field. Attackers can inject a large payload into the old password parameter during the change password process to bypass validation and set an arbitrary new password.

Sricam DeviceViewer 3.12.0.1 contains a password change security bypass vulnerability that allows authenticated users to change passwords without proper validation of the old password field. Attackers can inject a large payload into the old password parameter during the change password process to bypass validation and set an arbitrary new password.

EPSS

Процентиль: 8%
0.00027
Низкий

5.1 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-303

Связанные уязвимости

CVSS3: 6.5
nvd
3 месяца назад

Sricam DeviceViewer 3.12.0.1 contains a password change security bypass vulnerability that allows authenticated users to change passwords without proper validation of the old password field. Attackers can inject a large payload into the old password parameter during the change password process to bypass validation and set an arbitrary new password.

EPSS

Процентиль: 8%
0.00027
Низкий

5.1 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-303