Описание
Canlineapp Online 1.1 is vulnerable to Broken Access Control and allows users with the Auditor role to create an audit template as a result of improper authorization checks. This feature is designated for supervisor role, but auditors have been able to successfully create audit templates from their account.
Ссылки
- ExploitThird Party Advisory
- Not Applicable
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:henkel:canlineapp:1.1:*:*:*:*:*:*:*
EPSS
Процентиль: 32%
0.00121
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-863
Связанные уязвимости
CVSS3: 6.5
github
около 1 года назад
Canlineapp Online 1.1 is vulnerable to Broken Access Control and allows users with the Auditor role to create an audit template as a result of improper authorization checks. This feature is designated for supervisor role, but auditors have been able to successfully create audit templates from their account.
EPSS
Процентиль: 32%
0.00121
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-863