Описание
The “Study Edit” function of ShinHer StudyOnline System does not perform permission control. After logging in with user’s privilege, remote attackers can access and edit other users’ tutorial schedule by crafting URL parameters.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:xinheinformation:xinhe_teaching_platform_system:v2021:*:*:*:*:*:*:*
EPSS
Процентиль: 32%
0.00122
Низкий
5.4 Medium
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-285
CWE-862
Связанные уязвимости
CVSS3: 5.4
github
больше 3 лет назад
The “Study Edit” function of ShinHer StudyOnline System does not perform permission control. After logging in with user’s privilege, remote attackers can access and edit other users’ tutorial schedule by crafting URL parameters.
EPSS
Процентиль: 32%
0.00122
Низкий
5.4 Medium
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-285
CWE-862