Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-27990

Опубликовано: 14 апр. 2021
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

Appspace 6.2.4 is vulnerable to a broken authentication mechanism where pages such as /medianet/mail.aspx can be called directly and the framework is exposed with layouts, menus and functionalities.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:appspace:appspace:6.2.4:*:*:*:*:*:*:*

EPSS

Процентиль: 68%
0.00564
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 7.5
github
больше 3 лет назад

Appspace 6.2.4 is vulnerable to a broken authentication mechanism where pages such as /medianet/mail.aspx can be called directly and the framework is exposed with layouts, menus and functionalities.

EPSS

Процентиль: 68%
0.00564
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-287