Описание
A BOLA vulnerability in GET, PUT, DELETE /categories/{categoryId} allows a low privileged user to fetch, modify or delete the category of any user (including admin). This results in unauthorized access and unauthorized data manipulation.
Уязвимые конфигурации
Конфигурация 1Версия до 1.5.0 (исключая)
cpe:2.3:a:easyappointments:easyappointments:*:*:*:*:*:*:*:*
EPSS
Процентиль: 26%
0.00091
Низкий
8.5 High
CVSS3
8.1 High
CVSS3
Дефекты
CWE-639
CWE-639
Связанные уязвимости
CVSS3: 8.5
github
больше 1 года назад
A BOLA vulnerability in GET, PUT, DELETE /categories/{categoryId} allows a low privileged user to fetch, modify or delete the category of any user (including admin). This results in unauthorized access and unauthorized data manipulation.
EPSS
Процентиль: 26%
0.00091
Низкий
8.5 High
CVSS3
8.1 High
CVSS3
Дефекты
CWE-639
CWE-639