Логотип exploitDog
bind:CVE-2022-23383
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-23383

Количество 2

Количество 2

nvd логотип

CVE-2022-23383

почти 4 года назад

YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal home page, but the vulnerability can access other users' home pages through the non login status because real authentication is not carried out.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4cxv-rq6w-3ppq

почти 4 года назад

YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal home page, but the vulnerability can access other users' home pages through the non login status because real authentication is not carried out.

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-23383

YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal home page, but the vulnerability can access other users' home pages through the non login status because real authentication is not carried out.

CVSS3: 9.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-4cxv-rq6w-3ppq

YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal home page, but the vulnerability can access other users' home pages through the non login status because real authentication is not carried out.

CVSS3: 9.1
0%
Низкий
почти 4 года назад

Уязвимостей на страницу