Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q523-6vmw-xh76

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Open-School Community Edition 2.2 does not properly restrict access to the export functionality, which allows remote authenticated users to obtain sensitive information via the r parameter with the value export to index.php.

Open-School Community Edition 2.2 does not properly restrict access to the export functionality, which allows remote authenticated users to obtain sensitive information via the r parameter with the value export to index.php.

EPSS

Процентиль: 45%
0.00225
Низкий

Связанные уязвимости

CVSS3: 6.5
nvd
почти 6 лет назад

Open-School Community Edition 2.2 does not properly restrict access to the export functionality, which allows remote authenticated users to obtain sensitive information via the r parameter with the value export to index.php.

EPSS

Процентиль: 45%
0.00225
Низкий