Логотип exploitDog
bind:CVE-2025-58402
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-58402

Количество 2

Количество 2

nvd логотип

CVE-2025-58402

около 1 месяца назад

The CGM CLININET application uses direct, sequential object identifiers "MessageID" without proper authorization checks. By modifying the parameter in the GET request, an attacker can access messages and attachments belonging to other users.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-29jv-jj9x-v452

около 1 месяца назад

The CGM CLININET application uses direct, sequential object identifiers "MessageID" without proper authorization checks. By modifying the parameter in the GET request, an attacker can access messages and attachments belonging to other users.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-58402

The CGM CLININET application uses direct, sequential object identifiers "MessageID" without proper authorization checks. By modifying the parameter in the GET request, an attacker can access messages and attachments belonging to other users.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-29jv-jj9x-v452

The CGM CLININET application uses direct, sequential object identifiers "MessageID" without proper authorization checks. By modifying the parameter in the GET request, an attacker can access messages and attachments belonging to other users.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу