Описание
An issue in Audimex EE versions 15.1.20 and earlier allowing a remote attacker to escalate privileges. Analyzing the offline client code, it was identified that it is possible for any user (with any privilege) of Audimex to dump the whole Audimex database. This gives visibility upon password hashes of any user, ongoing audit data and more.
EPSS
Процентиль: 82%
0.01653
Низкий
8.8 High
CVSS3
Дефекты
CWE-276
Связанные уязвимости
CVSS3: 9.8
github
около 1 года назад
An issue in Audimex EE v.15.1.20 and before allows a remote attacker to escalate privileges.
EPSS
Процентиль: 82%
0.01653
Низкий
8.8 High
CVSS3
Дефекты
CWE-276