Логотип exploitDog
bind:CVE-2021-47721
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-47721

Количество 2

Количество 2

nvd логотип

CVE-2021-47721

около 2 месяцев назад

Orangescrum 1.8.0 contains a privilege escalation vulnerability that allows authenticated users to take over other project-assigned accounts by manipulating session cookies. Attackers can extract the victim's unique ID from the page source and replace their own session cookie to gain unauthorized access to another user's account.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-r5c3-xjh9-7vcw

около 2 месяцев назад

Orangescrum 1.8.0 contains a privilege escalation vulnerability that allows authenticated users to take over other project-assigned accounts by manipulating session cookies. Attackers can extract the victim's unique ID from the page source and replace their own session cookie to gain unauthorized access to another user's account.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-47721

Orangescrum 1.8.0 contains a privilege escalation vulnerability that allows authenticated users to take over other project-assigned accounts by manipulating session cookies. Attackers can extract the victim's unique ID from the page source and replace their own session cookie to gain unauthorized access to another user's account.

CVSS3: 8.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-r5c3-xjh9-7vcw

Orangescrum 1.8.0 contains a privilege escalation vulnerability that allows authenticated users to take over other project-assigned accounts by manipulating session cookies. Attackers can extract the victim's unique ID from the page source and replace their own session cookie to gain unauthorized access to another user's account.

CVSS3: 8.8
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу