Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r7rh-c7wm-cc7x

Опубликовано: 18 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5

Описание

Server-Side Access Control Bypass vulnerability in WombatDialer before 25.02 could allow unauthorized users to potentially call certain services without the necessary access level. This issue is limited to services used by the client (not the general-use JSON services) and requires reverse engineering of the proprietary serialization protocol, making it difficult to exploit.

Server-Side Access Control Bypass vulnerability in WombatDialer before 25.02 could allow unauthorized users to potentially call certain services without the necessary access level. This issue is limited to services used by the client (not the general-use JSON services) and requires reverse engineering of the proprietary serialization protocol, making it difficult to exploit.

EPSS

Процентиль: 23%
0.00078
Низкий

5 Medium

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 5
nvd
12 месяцев назад

Server-Side Access Control Bypass vulnerability in WombatDialer before 25.02 could allow unauthorized users to potentially call certain services without the necessary access level. This issue is limited to services used by the client (not the general-use JSON services) and requires reverse engineering of the proprietary serialization protocol, making it difficult to exploit.

EPSS

Процентиль: 23%
0.00078
Низкий

5 Medium

CVSS3

Дефекты

CWE-306