Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v435-c8wm-qmjm

Опубликовано: 14 мая 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can enable/disable the sharing rule of other users affecting the integrity of the application. Confidentiality and Availability are not affected.

Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can enable/disable the sharing rule of other users affecting the integrity of the application. Confidentiality and Availability are not affected.

EPSS

Процентиль: 37%
0.00156
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 4.3
nvd
больше 1 года назад

Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can enable/disable the sharing rule of other users affecting the integrity of the application. Confidentiality and Availability are not affected.

EPSS

Процентиль: 37%
0.00156
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862