Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-10778

Опубликовано: 03 авг. 2020
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled attribute from the fields since there is no server-side validation. This business logic flaw violate the expected behavior.

A business logic flaw was found in Red Hat CloudForms where the read-only values of the Widgets could be altered. An attacker with low privileges could bypass server-side validation by dropping the disabled attribute from the fields.

Дополнительная информация

Статус:

Important
Дефект:
CWE-501
https://bugzilla.redhat.com/show_bug.cgi?id=1847628CloudForms: Business logic bypass through widgets

EPSS

Процентиль: 56%
0.00877
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 6
nvd
около 6 лет назад

In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled attribute from the fields since there is no server-side validation. This business logic flaw violate the expected behavior.

CVSS3: 8.2
fstec
около 6 лет назад

Уязвимость программной платформы для управления виртуальными средами CloudForms Management Engine, связанная с недостатками механизма авторизации, позволяющая нарушителю редактировать виджеты, доступные только для чтения

EPSS

Процентиль: 56%
0.00877
Низкий

8.2 High

CVSS3