Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wxc7-jc57-c2hc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

The “Study Edit” function of ShinHer StudyOnline System does not perform permission control. After logging in with user’s privilege, remote attackers can access and edit other users’ tutorial schedule by crafting URL parameters.

The “Study Edit” function of ShinHer StudyOnline System does not perform permission control. After logging in with user’s privilege, remote attackers can access and edit other users’ tutorial schedule by crafting URL parameters.

EPSS

Процентиль: 32%
0.00122
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-285
CWE-862

Связанные уязвимости

CVSS3: 5.4
nvd
больше 4 лет назад

The “Study Edit” function of ShinHer StudyOnline System does not perform permission control. After logging in with user’s privilege, remote attackers can access and edit other users’ tutorial schedule by crafting URL parameters.

EPSS

Процентиль: 32%
0.00122
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-285
CWE-862