Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-44160

Опубликовано: 29 дек. 2021
Источник: nvd
CVSS3: 7.3
CVSS2: 7.5
EPSS Низкий

Описание

Carinal Tien Hospital Health Report System’s login page has improper authentication, a remote attacker can acquire another general user’s privilege by modifying the cookie parameter without authentication. The attacker can then perform limited operations on the system or modify data, making the service partially unavailable to the user.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cth:carinal_tien_hospital_health_report_system:-:*:*:*:*:*:*:*

EPSS

Процентиль: 69%
0.00592
Низкий

7.3 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-639
NVD-CWE-Other

Связанные уязвимости

CVSS3: 7.3
github
около 4 лет назад

Carinal Tien Hospital Health Report System’s login page has improper authentication, a remote attacker can acquire another general user’s privilege by modifying the cookie parameter without authentication. The attacker can then perform limited operations on the system or modify data, making the service partially unavailable to the user.

EPSS

Процентиль: 69%
0.00592
Низкий

7.3 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-639
NVD-CWE-Other