Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-40673

Опубликовано: 28 мая 2025
Источник: nvd
EPSS Низкий

Описание

A Missing Authorization vulnerability has been found in DinoRANK. This vulnerability allows an attacker to access invoices of any user via accessing endpoint '/facturas/YYYY-MM/SDRYYMM-XXXXX.pdf' because there is no access control. The pdf filename can be obtained via OSINT, insecure network traffic or brute force.

EPSS

Процентиль: 19%
0.0027
Низкий

Дефекты

CWE-862

Связанные уязвимости

github
около 1 года назад

A Missing Authorization vulnerability has been found in DinoRANK. This vulnerability allows an attacker to access invoices of any user via accessing endpoint '/facturas/YYYY-MM/SDRYYMM-XXXXX.pdf' because there is no access control. The pdf filename can be obtained via OSINT, insecure network traffic or brute force.

EPSS

Процентиль: 19%
0.0027
Низкий

Дефекты

CWE-862