Описание
Docassemble is an expert system for guided interviews and document assembly. The vulnerability allows attackers to gain unauthorized access to information on the system through URL manipulation. It affects versions 1.4.53 to 1.4.96. The vulnerability has been patched in version 1.4.97 of the master branch.
Ссылки
- Patch
- Third Party Advisory
- Patch
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 1.4.53 (включая) до 1.4.97 (исключая)
cpe:2.3:a:jhpyle:docassemble:*:*:*:*:*:*:*:*
EPSS
Процентиль: 100%
0.93891
Критический
7.5 High
CVSS3
Дефекты
CWE-706
Связанные уязвимости
CVSS3: 7.5
github
почти 2 года назад
Docassemble unauthorized access through URL manipulation
EPSS
Процентиль: 100%
0.93891
Критический
7.5 High
CVSS3
Дефекты
CWE-706