Описание
CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access content that should be restricted, resulting in full compromise of confidentiality, integrity, and availability of affected installations.
Уязвимые конфигурации
Конфигурация 1Версия от 15.4.8623 (включая) до 15.4.8630 (исключая)
cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:*
EPSS
Процентиль: 36%
0.00443
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-284
Связанные уязвимости
CVSS3: 9.8
github
2 месяца назад
CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access content that should be restricted, resulting in full compromise of confidentiality, integrity, and availability of affected installations.
EPSS
Процентиль: 36%
0.00443
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-284