7.5

CVE-2011-4677

One Click Orgs before 1.2.3 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OneclickorgsOne Click Orgs Version <= 1.2.2
OneclickorgsOne Click Orgs Version1.0.0
OneclickorgsOne Click Orgs Version1.0.1
OneclickorgsOne Click Orgs Version1.1.0
OneclickorgsOne Click Orgs Version1.1.1
OneclickorgsOne Click Orgs Version1.2.0
OneclickorgsOne Click Orgs Version1.2.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.52% 0.641
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.