Логотип exploitDog
bind:CVE-2025-26138
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-26138

Количество 2

Количество 2

nvd логотип

CVE-2025-26138

11 месяцев назад

Systemic Risk Value <=2.8.0 is vulnerable to improper access control in /RiskValue/GroupingEntities/Controls/GetFile.aspx?ID=. Uploaded files are accessible via a predictable numerical ID parameter, allowing unauthorized users to increment or decrement the ID to access and download files they do not have permission to view.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-mfc3-vh4c-cg3g

11 месяцев назад

Systemic Risk Value <=2.8.0 is vulnerable to improper access control in /RiskValue/GroupingEntities/Controls/GetFile.aspx?ID=. Uploaded files are accessible via a predictable numerical ID parameter, allowing unauthorized users to increment or decrement the ID to access and download files they do not have permission to view.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-26138

Systemic Risk Value <=2.8.0 is vulnerable to improper access control in /RiskValue/GroupingEntities/Controls/GetFile.aspx?ID=. Uploaded files are accessible via a predictable numerical ID parameter, allowing unauthorized users to increment or decrement the ID to access and download files they do not have permission to view.

CVSS3: 6.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-mfc3-vh4c-cg3g

Systemic Risk Value <=2.8.0 is vulnerable to improper access control in /RiskValue/GroupingEntities/Controls/GetFile.aspx?ID=. Uploaded files are accessible via a predictable numerical ID parameter, allowing unauthorized users to increment or decrement the ID to access and download files they do not have permission to view.

CVSS3: 6.5
0%
Низкий
11 месяцев назад

Уязвимостей на страницу