Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w2j7-cqvr-h9j4

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A privileged user can achieve code execution on the server via a ticket because of improper access control of uploaded resources. This might be exploitable in conjunction with CVE-2020-13992 by an unauthenticated attacker.

An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A privileged user can achieve code execution on the server via a ticket because of improper access control of uploaded resources. This might be exploitable in conjunction with CVE-2020-13992 by an unauthenticated attacker.

EPSS

Процентиль: 89%
0.04581
Низкий

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.8
nvd
больше 5 лет назад

An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A privileged user can achieve code execution on the server via a ticket because of improper access control of uploaded resources. This might be exploitable in conjunction with CVE-2020-13992 by an unauthenticated attacker.

EPSS

Процентиль: 89%
0.04581
Низкий

Дефекты

CWE-94