Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qr5q-3r8x-rmr4

Опубликовано: 23 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.3

Описание

ASUS WebStorage has a hardcoded API Token in the APP source code. An unauthenticated remote attacker can use this token to establish connections with the server and carry out login attempts to general user accounts. A successful login to a general user account allows the attacker to access, modify or delete this user account information.

ASUS WebStorage has a hardcoded API Token in the APP source code. An unauthenticated remote attacker can use this token to establish connections with the server and carry out login attempts to general user accounts. A successful login to a general user account allows the attacker to access, modify or delete this user account information.

EPSS

Процентиль: 82%
0.01715
Низкий

7.3 High

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 7.3
nvd
почти 4 года назад

ASUS WebStorage has a hardcoded API Token in the APP source code. An unauthenticated remote attacker can use this token to establish connections with the server and carry out login attempts to general user accounts. A successful login to a general user account allows the attacker to access, modify or delete this user account information.

EPSS

Процентиль: 82%
0.01715
Низкий

7.3 High

CVSS3

Дефекты

CWE-798