Описание
This vulnerability exists in Shilpi Client Dashboard due to improper handling of multiple parameters in the API endpoint. An authenticated remote attacker could exploit this vulnerability by including multiple “userid” parameters in the API request body leading to unauthorized access of sensitive information belonging to other users.
Ссылки
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 9.7.0 (исключая)
cpe:2.3:a:shilpi:client_dashboard:*:*:*:*:*:*:*:*
EPSS
Процентиль: 30%
0.00107
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-235
NVD-CWE-Other
Связанные уязвимости
CVSS3: 6.5
github
больше 1 года назад
This vulnerability exists in Shilpi Client Dashboard due to improper handling of multiple parameters in the API endpoint. An authenticated remote attacker could exploit this vulnerability by including multiple “userid” parameters in the API request body leading to unauthorized access of sensitive information belonging to other users.
EPSS
Процентиль: 30%
0.00107
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-235
NVD-CWE-Other