Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-3774

Опубликовано: 31 окт. 2022
Источник: nvd
CVSS3: 5.4
CVSS3: 9.1
EPSS Низкий

Описание

A vulnerability was found in SourceCodester Train Scheduler App 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /train_scheduler_app/?action=delete. The manipulation of the argument id leads to improper control of resource identifiers. The attack may be launched remotely. The identifier of this vulnerability is VDB-212504.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:train_scheduler_app_project:train_scheduler_app:1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 65%
0.005
Низкий

5.4 Medium

CVSS3

9.1 Critical

CVSS3

Дефекты

CWE-99

Связанные уязвимости

CVSS3: 9.1
github
больше 3 лет назад

A vulnerability was found in SourceCodester Train Scheduler App 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /train_scheduler_app/?action=delete. The manipulation of the argument id leads to improper control of resource identifiers. The attack may be launched remotely. The identifier of this vulnerability is VDB-212504.

EPSS

Процентиль: 65%
0.005
Низкий

5.4 Medium

CVSS3

9.1 Critical

CVSS3

Дефекты

CWE-99