Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xwrh-qw65-q9mr

Опубликовано: 09 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9

Описание

Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Insufficient tenant-level authorization checks allow authenticated users to access administrative resources belonging to other tenants by specifying a valid non predictable tenant identifier.

Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Insufficient tenant-level authorization checks allow authenticated users to access administrative resources belonging to other tenants by specifying a valid non predictable tenant identifier.

EPSS

Процентиль: 7%
0.0017
Низкий

9 Critical

CVSS4

Дефекты

CWE-639

Связанные уязвимости

nvd
10 дней назад

Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Insufficient tenant-level authorization checks allow authenticated users to access administrative resources belonging to other tenants by specifying a valid non predictable tenant identifier.

EPSS

Процентиль: 7%
0.0017
Низкий

9 Critical

CVSS4

Дефекты

CWE-639