Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vmrp-q2j9-gmqr

Опубликовано: 26 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 2.2

Описание

When a URL is added to the map element, it is recorded in the database with sequential IDs. Upon adding a new URL, the system retrieves the last sysmapelementurlid value and increments it by one. However, an issue arises when a user manually changes the sysmapelementurlid value by adding sysmapelementurlid + 1. This action prevents others from adding URLs to the map element.

When a URL is added to the map element, it is recorded in the database with sequential IDs. Upon adding a new URL, the system retrieves the last sysmapelementurlid value and increments it by one. However, an issue arises when a user manually changes the sysmapelementurlid value by adding sysmapelementurlid + 1. This action prevents others from adding URLs to the map element.

EPSS

Процентиль: 26%
0.00085
Низкий

2.2 Low

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 2.2
ubuntu
7 месяцев назад

When a URL is added to the map element, it is recorded in the database with sequential IDs. Upon adding a new URL, the system retrieves the last sysmapelementurlid value and increments it by one. However, an issue arises when a user manually changes the sysmapelementurlid value by adding sysmapelementurlid + 1. This action prevents others from adding URLs to the map element.

CVSS3: 2.2
nvd
7 месяцев назад

When a URL is added to the map element, it is recorded in the database with sequential IDs. Upon adding a new URL, the system retrieves the last sysmapelementurlid value and increments it by one. However, an issue arises when a user manually changes the sysmapelementurlid value by adding sysmapelementurlid + 1. This action prevents others from adding URLs to the map element.

CVSS3: 2.2
debian
7 месяцев назад

When a URL is added to the map element, it is recorded in the database ...

CVSS3: 2.2
fstec
7 месяцев назад

Уязвимость сервера универсальной системы мониторинга Zabbix, связанная с недостаточной проверкой входных данных, позволяющая нарушителю повысить свои привилегии

CVSS3: 9.1
redos
5 месяцев назад

Множественные уязвимости zabbix-server-pgsql

EPSS

Процентиль: 26%
0.00085
Низкий

2.2 Low

CVSS3

Дефекты

CWE-20