Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rj4p-qc9g-j2p3

Опубликовано: 05 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.3

Описание

The SolisCloud API suffers from a Broken Access Control vulnerability, specifically an Insecure Direct Object Reference (IDOR), where any authenticated user can access detailed data of any plant by altering the plant_id in the request.

The SolisCloud API suffers from a Broken Access Control vulnerability, specifically an Insecure Direct Object Reference (IDOR), where any authenticated user can access detailed data of any plant by altering the plant_id in the request.

EPSS

Процентиль: 15%
0.0005
Низкий

8.3 High

CVSS4

Дефекты

CWE-639

Связанные уязвимости

nvd
2 месяца назад

The SolisCloud API suffers from a Broken Access Control vulnerability, specifically an Insecure Direct Object Reference (IDOR), where any authenticated user can access detailed data of any plant by altering the plant_id in the request.

EPSS

Процентиль: 15%
0.0005
Низкий

8.3 High

CVSS4

Дефекты

CWE-639