7.5
CVE-2020-35737
- EPSS 10.84%
- Veröffentlicht 30.12.2020 20:15:15
- Zuletzt bearbeitet 21.11.2024 05:27:58
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information by manipulating the unvalidated UserIndex parameter, aka Insecure Direct Object Reference.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Newgensoft ≫ Egov Version12.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 10.84% | 0.932 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|