Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-1946

Опубликовано: 10 апр. 2018
Источник: nvd
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

OpenDocMan 1.2.7 and earlier does not properly validate allowed actions, which allows remote authenticated users to bypass an intended access restrictions and assign administrative privileges to themselves via a crafted request to signup.php.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:opendocman:opendocman:*:*:*:*:*:*:*:*
Версия до 1.2.7 (включая)

EPSS

Процентиль: 73%
0.00787
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

OpenDocMan 1.2.7 and earlier does not properly validate allowed actions, which allows remote authenticated users to bypass an intended access restrictions and assign administrative privileges to themselves via a crafted request to signup.php.

EPSS

Процентиль: 73%
0.00787
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-264