Описание
The Administrator function of EasyTest has an Incorrect Authorization vulnerability. A remote attacker authenticated as a general user can exploit this vulnerability to bypass the intended access restrictions, to make API functions calls, manipulate system and terminate service.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 17l18s (включая) до 22i26 (исключая)
cpe:2.3:a:easy_test_project:easy_test:*:*:*:*:*:*:*:*
EPSS
Процентиль: 56%
0.00343
Низкий
8.8 High
CVSS3
Дефекты
CWE-863
CWE-863
Связанные уязвимости
CVSS3: 8.8
github
около 3 лет назад
The Administrator function of EasyTest has an Incorrect Authorization vulnerability. A remote attacker authenticated as a general user can exploit this vulnerability to bypass the intended access restrictions, to make API functions calls, manipulate system and terminate service.
EPSS
Процентиль: 56%
0.00343
Низкий
8.8 High
CVSS3
Дефекты
CWE-863
CWE-863