Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-13040

Опубликовано: 31 дек. 2024
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

The QOCA aim from Quanta Computer has an Authorization Bypass Through User-Controlled Key vulnerability. By controlling the user ID parameter, remote attackers with regular privileges could access certain features as any user, modify any user's account information and privileges, leading to privilege escalation.

EPSS

Процентиль: 46%
0.00237
Низкий

8.8 High

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 8.8
github
около 1 года назад

The QOCA aim from Quanta Computer has an Authorization Bypass Through User-Controlled Key vulnerability. By controlling the user ID parameter, remote attackers with regular privileges could access certain features as any user, modify any user's account information and privileges, leading to privilege escalation.

EPSS

Процентиль: 46%
0.00237
Низкий

8.8 High

CVSS3

Дефекты

CWE-639