Описание
SoPlanning before 1.47 doesn't correctly check the security key used to publicly share plannings. It allows a bypass to get access without authentication.
Ссылки
- ExploitPatchThird Party Advisory
- ExploitPatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.47 (исключая)
cpe:2.3:a:soplanning:soplanning:*:*:*:*:*:*:*:*
EPSS
Процентиль: 97%
0.31321
Средний
5.3 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-287
Связанные уязвимости
github
около 3 лет назад
SoPlanning before 1.47 doesn't correctly check the security key used to publicly share plannings. It allows a bypass to get access without authentication.
EPSS
Процентиль: 97%
0.31321
Средний
5.3 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-287