Описание
ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated attackers (who are, by design, able to have a security token).
Ссылки
- ExploitThird Party Advisory
- ExploitMailing ListThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party Advisory
- ExploitMailing ListThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 1.4.3 (исключая)
cpe:2.3:a:impresscms:impresscms:*:*:*:*:*:*:*:*
EPSS
Процентиль: 99%
0.76068
Высокий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-287
Связанные уязвимости
EPSS
Процентиль: 99%
0.76068
Высокий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-287