4.3

CVE-2020-9013

Exploit
Arvato Skillpipe 3.0 allows attackers to bypass intended print restrictions by deleting <div id="watermark"> from the HTML source code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ArvatoSkillpipe Version3.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.29% 0.665
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://twitter.com/GerardFuguet/status/1228462263188758529
Third Party Advisory
https://www.exploit-db.com/docs/48175
Third Party Advisory
Exploit
VDB Entry
https://www.youtube.com/watch?v=Ok1UmRFWoLY
Third Party Advisory