Логотип exploitDog
bind:CVE-2022-29287
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-29287

Количество 2

Количество 2

nvd логотип

CVE-2022-29287

почти 4 года назад

Kentico CMS before 13.0.66 has an Insecure Direct Object Reference vulnerability. It allows an attacker with user management rights (default is Administrator) to export the user options of any user, even ones with higher privileges (like Global Administrators) than the current user. The exported XML contains every option of the exported user (even the hashed password).

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-f28x-5fx8-2j2h

почти 4 года назад

Kentico CMS before 13.0.66 has an Insecure Direct Object Reference vulnerability. It allows an attacker with user management rights (default is Administrator) to export the user options of any user, even ones with higher privileges (like Global Administrators) than the current user. The exported XML contains every option of the exported user (even the hashed password).

CVSS3: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-29287

Kentico CMS before 13.0.66 has an Insecure Direct Object Reference vulnerability. It allows an attacker with user management rights (default is Administrator) to export the user options of any user, even ones with higher privileges (like Global Administrators) than the current user. The exported XML contains every option of the exported user (even the hashed password).

CVSS3: 4.9
0%
Низкий
почти 4 года назад
github логотип
GHSA-f28x-5fx8-2j2h

Kentico CMS before 13.0.66 has an Insecure Direct Object Reference vulnerability. It allows an attacker with user management rights (default is Administrator) to export the user options of any user, even ones with higher privileges (like Global Administrators) than the current user. The exported XML contains every option of the exported user (even the hashed password).

CVSS3: 4.9
0%
Низкий
почти 4 года назад

Уязвимостей на страницу