Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-18626

Опубликовано: 25 мар. 2020
Источник: nvd
CVSS3: 4.3
CVSS2: 4
EPSS Низкий

Описание

Harris Ormed Self Service before 2019.1.4 allows an authenticated user to view W-2 forms belonging to other users via an arbitrary empNo value to the ORMEDMIS/Data/PY/T4W2Service.svc/RetrieveW2EntriesForEmployee URI, thus exposing sensitive information including employee tax information, social security numbers, home addresses, and more.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:harriscomputer:ormed_mis:*:*:*:*:*:*:*:*
Версия до 2019.1.4 (исключая)

EPSS

Процентиль: 57%
0.0035
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-639

Связанные уязвимости

github
больше 3 лет назад

Harris Ormed Self Service before 2019.1.4 allows an authenticated user to view W-2 forms belonging to other users via an arbitrary empNo value to the ORMEDMIS/Data/PY/T4W2Service.svc/RetrieveW2EntriesForEmployee URI, thus exposing sensitive information including employee tax information, social security numbers, home addresses, and more.

EPSS

Процентиль: 57%
0.0035
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-639