Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qr8q-6c25-rppr

Опубликовано: 20 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6

Описание

Flowise before 3.1.2 contains a mass assignment vulnerability in the PUT /api/v1/user endpoint that allows authenticated users to directly modify the credential field without validation. Attackers can bypass password change verification and session invalidation by supplying a crafted password hash, establishing persistent account access after temporary session compromise.

Flowise before 3.1.2 contains a mass assignment vulnerability in the PUT /api/v1/user endpoint that allows authenticated users to directly modify the credential field without validation. Attackers can bypass password change verification and session invalidation by supplying a crafted password hash, establishing persistent account access after temporary session compromise.

EPSS

Процентиль: 30%
0.00366
Низкий

6 Medium

CVSS4

Дефекты

CWE-915

Связанные уязвимости

nvd
3 месяца назад

Flowise before 3.1.2 contains a mass assignment vulnerability in the PUT /api/v1/user endpoint that allows authenticated users to directly modify the credential field without validation. Attackers can bypass password change verification and session invalidation by supplying a crafted password hash, establishing persistent account access after temporary session compromise.

EPSS

Процентиль: 30%
0.00366
Низкий

6 Medium

CVSS4

Дефекты

CWE-915