Описание
An issue in the API endpoint /AccountMaster/GetCurrentUserInfo of INROAD before v202402060 allows attackers to access sensitive information via a crafted payload to the UserNameOrPhoneNumber parameter.
EPSS
Процентиль: 73%
0.00768
Низкий
5.9 Medium
CVSS3
Дефекты
CWE-922
Связанные уязвимости
CVSS3: 5.9
github
больше 1 года назад
An issue in the API endpoint /AccountMaster/GetCurrentUserInfo of INROAD before v202402060 allows attackers to access sensitive information via a crafted payload to the UserNameOrPhoneNumber parameter.
EPSS
Процентиль: 73%
0.00768
Низкий
5.9 Medium
CVSS3
Дефекты
CWE-922