Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q3x9-28f7-w8rc

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Total.js CMS Unauthorized Access

An issue was discovered in Total.js CMS 12.0.0. An authenticated user with limited privileges can get access to a resource that they do not own by calling the associated API. The product correctly manages privileges only for the front-end resource path, not for API requests. This leads to vertical and horizontal privilege escalation.

Пакеты

Наименование

total4

npm
Затронутые версииВерсия исправления

= 12.0

Отсутствует

EPSS

Процентиль: 72%
0.00705
Низкий

8.8 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 8.8
nvd
больше 6 лет назад

An issue was discovered in Total.js CMS 12.0.0. An authenticated user with limited privileges can get access to a resource that they do not own by calling the associated API. The product correctly manages privileges only for the front-end resource path, not for API requests. This leads to vertical and horizontal privilege escalation.

EPSS

Процентиль: 72%
0.00705
Низкий

8.8 High

CVSS3

Дефекты

CWE-862