Описание
A security vulnerability has been detected in macrozheng mall up to 1.0.3. This vulnerability affects unknown code of the file /member/address/update/ of the component Member Endpoint. The manipulation leads to improper authorization. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Ссылки
- ExploitIssue TrackingThird Party Advisory
- Permissions RequiredVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 1.0.3 (включая)
cpe:2.3:a:macrozheng:mall:*:*:*:*:*:*:*:*
EPSS
Процентиль: 12%
0.0004
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-266
Связанные уязвимости
CVSS3: 4.3
github
около 1 месяца назад
A security vulnerability has been detected in macrozheng mall up to 1.0.3. This vulnerability affects unknown code of the file /member/address/update/ of the component Member Endpoint. The manipulation leads to improper authorization. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
EPSS
Процентиль: 12%
0.0004
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-266