Описание
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request.
Ссылки
- ExploitMitigationThird Party Advisory
- Product
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:webkul:krayin_crm:2.2.0:*:*:*:*:*:*:*
EPSS
Процентиль: 28%
0.00351
Низкий
8.1 High
CVSS3
Дефекты
CWE-639
Связанные уязвимости
CVSS3: 8.1
github
4 месяца назад
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
EPSS
Процентиль: 28%
0.00351
Низкий
8.1 High
CVSS3
Дефекты
CWE-639