Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rpgw-w8c6-24xw

Опубликовано: 22 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control. The Web panel allows users to gain access to potentially sensitive API calls such as listing users and their data, file management API calls and audit-related API calls.

Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control. The Web panel allows users to gain access to potentially sensitive API calls such as listing users and their data, file management API calls and audit-related API calls.

EPSS

Процентиль: 20%
0.00063
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 5.4
nvd
около 2 лет назад

Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control. The Web panel allows users to gain access to potentially sensitive API calls such as listing users and their data, file management API calls and audit-related API calls.

EPSS

Процентиль: 20%
0.00063
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-639