Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-0967

Опубликовано: 05 апр. 2023
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Bhima version 1.27.0 allows an attacker authenticated with normal user permissions to view sensitive data of other application users and data that should only be viewed by the administrator. This is possible because the application is vulnerable to IDOR, it does not properly validate user permissions with respect to certain actions the user can perform.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:imaworldhealth:bhima:1.27.0:*:*:*:*:*:*:*

EPSS

Процентиль: 21%
0.0007
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-639
CWE-639

Связанные уязвимости

CVSS3: 6.5
github
почти 3 года назад

Bhima version 1.27.0 allows an attacker authenticated with normal user permissions to view sensitive data of other application users and data that should only be viewed by the administrator. This is possible because the application is vulnerable to IDOR, it does not properly validate user permissions with respect to certain actions the user can perform.

EPSS

Процентиль: 21%
0.0007
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-639
CWE-639