Логотип exploitDog
bind:CVE-2022-22107
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-22107

Количество 2

Количество 2

nvd логотип

CVE-2022-22107

около 4 лет назад

In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privileges account (employee type user), can view the appointments of all users in the system including administrators. However, this type of user is not authorized to view the calendar at all.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-44gv-fgcj-w546

около 4 лет назад

Missing Authorization in DayByDay CRM

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-22107

In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privileges account (employee type user), can view the appointments of all users in the system including administrators. However, this type of user is not authorized to view the calendar at all.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-44gv-fgcj-w546

Missing Authorization in DayByDay CRM

CVSS3: 4.3
0%
Низкий
около 4 лет назад

Уязвимостей на страницу