Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rqg6-587c-h9v3

Опубликовано: 16 июн. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

An unauthenticated remote attacker can take advantage of the current overly permissive CORS policy to gain access and read the responses, potentially exposing sensitive data or enabling further attacks.

An unauthenticated remote attacker can take advantage of the current overly permissive CORS policy to gain access and read the responses, potentially exposing sensitive data or enabling further attacks.

EPSS

Процентиль: 35%
0.00421
Низкий

8.8 High

CVSS3

Дефекты

CWE-942

Связанные уязвимости

CVSS3: 6.5
nvd
около 1 года назад

An unauthenticated remote attacker can trick an admin to visit a website containing malicious java script code. The current overly permissive CORS policy allows the attacker to obtain any files from the file system.

CVSS3: 8.8
fstec
больше 1 года назад

Уязвимость программного средства для настройки и параметризации контроллеров WAGO Device Manager, связанная с ошибками конфигурации политики CORS, позволяющая нарушителю получить несанкционированный доступ к файловой системе

EPSS

Процентиль: 35%
0.00421
Низкий

8.8 High

CVSS3

Дефекты

CWE-942