Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xrqj-45rp-23mg

Опубликовано: 28 мая 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.3

Описание

A Missing Authorization vulnerability has been found in DinoRANK. This vulnerability allows an attacker to access invoices of any user via accessing endpoint '/facturas/YYYY-MM/SDRYYMM-XXXXX.pdf' because there is no access control. The pdf filename can be obtained via OSINT, insecure network traffic or brute force.

A Missing Authorization vulnerability has been found in DinoRANK. This vulnerability allows an attacker to access invoices of any user via accessing endpoint '/facturas/YYYY-MM/SDRYYMM-XXXXX.pdf' because there is no access control. The pdf filename can be obtained via OSINT, insecure network traffic or brute force.

EPSS

Процентиль: 19%
0.00061
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-862

Связанные уязвимости

nvd
9 месяцев назад

A Missing Authorization vulnerability has been found in DinoRANK. This vulnerability allows an attacker to access invoices of any user via accessing endpoint '/facturas/YYYY-MM/SDRYYMM-XXXXX.pdf' because there is no access control. The pdf filename can be obtained via OSINT, insecure network traffic or brute force.

EPSS

Процентиль: 19%
0.00061
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-862