Описание
An indirect Object Reference (IDOR) in the Order and Invoice pages in Floorsight Customer Portal Q3 2023 allows an unauthenticated remote attacker to view sensitive customer information.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до q3_2023 (включая)
cpe:2.3:a:floorsightsoftware:customer_portal:*:*:*:*:*:*:*:*
EPSS
Процентиль: 77%
0.01006
Низкий
7.5 High
CVSS3
Дефекты
CWE-639
CWE-639
Связанные уязвимости
CVSS3: 7.5
github
около 2 лет назад
An indirect Object Reference (IDOR) in the Order and Invoice pages in Floorsight Customer Portal Q3 2023 allows an unauthenticated remote attacker to view sensitive customer information.
EPSS
Процентиль: 77%
0.01006
Низкий
7.5 High
CVSS3
Дефекты
CWE-639
CWE-639