Описание
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker to obtain a token with administrative privileges for the entire platform via the createToken GraphQL mutation.
Ссылки
- ExploitThird Party Advisory
- Permissions Required
- Not Applicable
- Press/Media CoverageThird Party Advisory
- Press/Media CoverageThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2025-09-06 (включая)
cpe:2.3:a:rbi:restaurant_brands_international_assistant:*:*:*:*:*:*:*:*
EPSS
Процентиль: 48%
0.00245
Низкий
9.9 Critical
CVSS3
Дефекты
CWE-266
Связанные уязвимости
CVSS3: 9.9
github
4 месяца назад
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker to obtain a token with administrative privileges for the entire platform via the createToken GraphQL mutation.
EPSS
Процентиль: 48%
0.00245
Низкий
9.9 Critical
CVSS3
Дефекты
CWE-266