Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r6xp-85fr-87p6

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited and logged into, resulting in information disclosure (at a minimum) and often escalation of privileges.

In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited and logged into, resulting in information disclosure (at a minimum) and often escalation of privileges.

EPSS

Процентиль: 62%
0.00428
Низкий

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 9.8
nvd
больше 4 лет назад

In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited and logged into, resulting in information disclosure (at a minimum) and often escalation of privileges.

CVSS3: 9.8
debian
больше 4 лет назад

In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account a ...

EPSS

Процентиль: 62%
0.00428
Низкий

Дефекты

CWE-613