Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rf85-wq6p-mgqc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

newbee-mall all versions are affected by incorrect access control to remotely gain privileges through AdminLoginInterceptor.java. The authentication logic of the system's background /admin is in code AdminLoginInterceptor, which can be bypassed.

newbee-mall all versions are affected by incorrect access control to remotely gain privileges through AdminLoginInterceptor.java. The authentication logic of the system's background /admin is in code AdminLoginInterceptor, which can be bypassed.

EPSS

Процентиль: 60%
0.00398
Низкий

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.8
nvd
около 5 лет назад

newbee-mall all versions are affected by incorrect access control to remotely gain privileges through AdminLoginInterceptor.java. The authentication logic of the system's background /admin is in code AdminLoginInterceptor, which can be bypassed.

EPSS

Процентиль: 60%
0.00398
Низкий

Дефекты

CWE-287