Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xh7c-xrrg-3jv2

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

An Insecure Direct Object Reference (IDOR) vulnerability was found in Prestashop Opart devis < 4.0.2. Unauthenticated attackers can have access to any user's invoice and delivery address by exploiting an IDOR on the delivery_address and invoice_address fields.

An Insecure Direct Object Reference (IDOR) vulnerability was found in Prestashop Opart devis < 4.0.2. Unauthenticated attackers can have access to any user's invoice and delivery address by exploiting an IDOR on the delivery_address and invoice_address fields.

EPSS

Процентиль: 74%
0.0084
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-20
CWE-639

Связанные уязвимости

CVSS3: 5.3
nvd
около 5 лет назад

An Insecure Direct Object Reference (IDOR) vulnerability was found in Prestashop Opart devis < 4.0.2. Unauthenticated attackers can have access to any user's invoice and delivery address by exploiting an IDOR on the delivery_address and invoice_address fields.

EPSS

Процентиль: 74%
0.0084
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-20
CWE-639