Логотип exploitDog
bind:CVE-2022-22111
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-22111

Количество 2

Количество 2

nvd логотип

CVE-2022-22111

около 4 лет назад

In DayByDay CRM, version 2.2.0 is vulnerable to missing authorization. Any application user in the application who has update user permission enabled is able to change the password of other users, including the administrator’s. This allows the attacker to gain access to the highest privileged user in the application.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-w6rp-4vj7-v2m8

около 4 лет назад

Missing Authorization in DayByDay CRM

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-22111

In DayByDay CRM, version 2.2.0 is vulnerable to missing authorization. Any application user in the application who has update user permission enabled is able to change the password of other users, including the administrator’s. This allows the attacker to gain access to the highest privileged user in the application.

CVSS3: 8.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-w6rp-4vj7-v2m8

Missing Authorization in DayByDay CRM

CVSS3: 8.8
0%
Низкий
около 4 лет назад

Уязвимостей на страницу