Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qj2m-h9cr-4gv7

Опубликовано: 16 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The API in Accredible Credential.net December 6th, 2023 allows an Insecure Direct Object Reference attack that discloses partial information about certificates and their respective holder. NOTE: the excellium-services.com web page about this issue mentions "Vendor says that it's not a security issue."

The API in Accredible Credential.net December 6th, 2023 allows an Insecure Direct Object Reference attack that discloses partial information about certificates and their respective holder. NOTE: the excellium-services.com web page about this issue mentions "Vendor says that it's not a security issue."

EPSS

Процентиль: 51%
0.00284
Низкий

7.5 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.5
nvd
почти 2 года назад

The API in Accredible Credential.net December 6th, 2023 allows an Insecure Direct Object Reference attack that discloses partial information about certificates and their respective holder. NOTE: the excellium-services.com web page about this issue mentions "Vendor says that it's not a security issue."

EPSS

Процентиль: 51%
0.00284
Низкий

7.5 High

CVSS3

Дефекты

CWE-200