Описание
A vulnerability has been found in code-projects Invoice System in Laravel 1.0. Affected is an unknown function of the file /profile/ of the component Profile Handler. Such manipulation of the argument ID leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
EPSS
Процентиль: 10%
0.00201
Низкий
6.3 Medium
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-266
Связанные уязвимости
CVSS3: 6.3
github
3 месяца назад
A vulnerability has been found in code-projects Invoice System in Laravel 1.0. Affected is an unknown function of the file /profile/ of the component Profile Handler. Such manipulation of the argument ID leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
EPSS
Процентиль: 10%
0.00201
Низкий
6.3 Medium
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-266