Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rjf6-hfqr-mx5v

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Newgen OmniDocs allows remote attackers to bypass intended access restrictions via (1) a modified FolderRights parameter to doccab/doclist.jsp, which leads to arbitrary permission changes; or (2) a modified UserIndex parameter to doccab/userprofile/editprofile.jsp, which selects the settings page of an arbitrary user.

Newgen OmniDocs allows remote attackers to bypass intended access restrictions via (1) a modified FolderRights parameter to doccab/doclist.jsp, which leads to arbitrary permission changes; or (2) a modified UserIndex parameter to doccab/userprofile/editprofile.jsp, which selects the settings page of an arbitrary user.

EPSS

Процентиль: 77%
0.01082
Низкий

Связанные уязвимости

nvd
больше 14 лет назад

Newgen OmniDocs allows remote attackers to bypass intended access restrictions via (1) a modified FolderRights parameter to doccab/doclist.jsp, which leads to arbitrary permission changes; or (2) a modified UserIndex parameter to doccab/userprofile/editprofile.jsp, which selects the settings page of an arbitrary user.

EPSS

Процентиль: 77%
0.01082
Низкий