9.8
CVE-2021-25648
- EPSS 1.17%
- Veröffentlicht 16.02.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:55:12
- Erkennungen
Mobile application "Testes de Codigo" 11.4 and prior allows an attacker to gain access to the administrative interface and premium features by tampering the boolean value of parameters "isAdmin" and "isPremium" located on device storage.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Testes-codigo ≫ Testes De Codigo SwPlatform android Version <= 11.4
Testes-codigo ≫ Testes De Codigo SwPlatform iphone_os Version <= 11.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.17% | 0.632 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
https://vrls.ws/posts/2021/02/cve-2021-25648-mobile-application-testes-de-codigo-privilege-escalation/