Логотип exploitDog
bind:CVE-2020-37094
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-37094

Количество 2

Количество 2

nvd логотип

CVE-2020-37094

5 дней назад

EspoCRM 5.8.5 contains an authentication vulnerability that allows attackers to access other user accounts by manipulating authorization headers. Attackers can decode and modify Basic Authorization and Espo-Authorization tokens to gain unauthorized access to administrative user information and privileges.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-wcm6-243c-86f3

5 дней назад

EspoCRM 5.8.5 contains an authentication vulnerability that allows attackers to access other user accounts by manipulating authorization headers. Attackers can decode and modify Basic Authorization and Espo-Authorization tokens to gain unauthorized access to administrative user information and privileges.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-37094

EspoCRM 5.8.5 contains an authentication vulnerability that allows attackers to access other user accounts by manipulating authorization headers. Attackers can decode and modify Basic Authorization and Espo-Authorization tokens to gain unauthorized access to administrative user information and privileges.

CVSS3: 9.8
0%
Низкий
5 дней назад
github логотип
GHSA-wcm6-243c-86f3

EspoCRM 5.8.5 contains an authentication vulnerability that allows attackers to access other user accounts by manipulating authorization headers. Attackers can decode and modify Basic Authorization and Espo-Authorization tokens to gain unauthorized access to administrative user information and privileges.

CVSS3: 9.8
0%
Низкий
5 дней назад

Уязвимостей на страницу