Логотип exploitDog
bind:CVE-2020-36124
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-36124

Количество 2

Количество 2

nvd логотип

CVE-2020-36124

почти 5 лет назад

Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by XML External Entity (XXE) injection. An authenticated attacker can compromise the private keys of a JWT token and reuse them to manipulate the access tokens to access the platform as any desired user (clients and administrators).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-hr2v-vc99-3c32

больше 3 лет назад

Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by XML External Entity (XXE) injection. An authenticated attacker can compromise the private keys of a JWT token and reuse them to manipulate the access tokens to access the platform as any desired user (clients and administrators).

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-36124

Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by XML External Entity (XXE) injection. An authenticated attacker can compromise the private keys of a JWT token and reuse them to manipulate the access tokens to access the platform as any desired user (clients and administrators).

CVSS3: 6.5
1%
Низкий
почти 5 лет назад
github логотип
GHSA-hr2v-vc99-3c32

Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by XML External Entity (XXE) injection. An authenticated attacker can compromise the private keys of a JWT token and reuse them to manipulate the access tokens to access the platform as any desired user (clients and administrators).

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу