Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-17605

Опубликовано: 07 нояб. 2019
Источник: nvd
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

A mass assignment vulnerability in eyecomms eyeCMS through 2019-10-15 allows any candidate to take over another candidate's account (by also exploiting CVE-2019-17604) via a modified candidate id and an additional password parameter. The outcome is that the password of this other candidate is changed.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:eyecomms:eyecms:*:*:*:*:*:*:*:*
Версия до 2019-10-15 (включая)

EPSS

Процентиль: 58%
0.00359
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-639

Связанные уязвимости

github
больше 3 лет назад

A mass assignment vulnerability in eyecomms eyeCMS through 2019-10-15 allows any candidate to take over another candidate's account (by also exploiting CVE-2019-17604) via a modified candidate id and an additional password parameter. The outcome is that the password of this other candidate is changed.

EPSS

Процентиль: 58%
0.00359
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-639