Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-40673

Опубликовано: 28 мая 2025
Источник: nvd
EPSS Низкий

Описание

A Missing Authorization vulnerability has been found in DinoRANK. This vulnerability allows an attacker to access invoices of any user via accessing endpoint '/facturas/YYYY-MM/SDRYYMM-XXXXX.pdf' because there is no access control. The pdf filename can be obtained via OSINT, insecure network traffic or brute force.

EPSS

Процентиль: 18%
0.00056
Низкий

Дефекты

CWE-862

Связанные уязвимости

github
9 месяцев назад

A Missing Authorization vulnerability has been found in DinoRANK. This vulnerability allows an attacker to access invoices of any user via accessing endpoint '/facturas/YYYY-MM/SDRYYMM-XXXXX.pdf' because there is no access control. The pdf filename can be obtained via OSINT, insecure network traffic or brute force.

EPSS

Процентиль: 18%
0.00056
Низкий

Дефекты

CWE-862