Логотип exploitDog
bind:CVE-2022-23055
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-23055

Количество 2

Количество 2

nvd логотип

CVE-2022-23055

больше 3 лет назад

In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker can send a direct message or a group message to any member or group, impersonating themselves as the administrator. The attacker can also read chat messages of groups that they do not belong to, and of other users.

CVSS2: 5.5
EPSS: Низкий
github логотип

GHSA-gxgf-4cfv-cmq2

больше 3 лет назад

In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker can send a direct message or a group message to any member or group, impersonating themselves as the administrator. The attacker can also read chat messages of groups that they do not belong to, and of other users.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-23055

In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker can send a direct message or a group message to any member or group, impersonating themselves as the administrator. The attacker can also read chat messages of groups that they do not belong to, and of other users.

CVSS2: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-gxgf-4cfv-cmq2

In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker can send a direct message or a group message to any member or group, impersonating themselves as the administrator. The attacker can also read chat messages of groups that they do not belong to, and of other users.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу