Описание
YOURLS through 1.7.3 is affected by a type juggling vulnerability in the api component that can result in login bypass.
Ссылки
- ExploitThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Release NotesThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Release NotesThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.7.3 (включая)
cpe:2.3:a:yourls:yourls:*:*:*:*:*:*:*:*
EPSS
Процентиль: 94%
0.14963
Средний
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-843
Связанные уязвимости
CVSS3: 9.8
github
больше 6 лет назад
Access of Resource Using Incompatible Type ('Type Confusion') in yourls/yourls
EPSS
Процентиль: 94%
0.14963
Средний
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-843