Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xw8r-2c2x-7j88

Опубликовано: 10 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

By knowing an organization's ID, an attacker can join the organization without permission and gain the ability to read and modify all data within that organization. This vulnerability allows unauthorized access and modification of sensitive information, posing a significant security risk. The flaw is due to insufficient verification of user permissions when joining an organization.

By knowing an organization's ID, an attacker can join the organization without permission and gain the ability to read and modify all data within that organization. This vulnerability allows unauthorized access and modification of sensitive information, posing a significant security risk. The flaw is due to insufficient verification of user permissions when joining an organization.

EPSS

Процентиль: 32%
0.00121
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 9.1
nvd
больше 1 года назад

By knowing an organization's ID, an attacker can join the organization without permission and gain the ability to read and modify all data within that organization. This vulnerability allows unauthorized access and modification of sensitive information, posing a significant security risk. The flaw is due to insufficient verification of user permissions when joining an organization.

EPSS

Процентиль: 32%
0.00121
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-200