6.5
CVE-2021-34369
- EPSS 6.77%
- Veröffentlicht 09.06.2021 12:15:08
- Zuletzt bearbeitet 21.11.2024 06:10:14
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
portlets/contact/ref/refContactDetail.do in Accela Civic Platform through 20.1 allows remote attackers to obtain sensitive information via a modified contactSeqNumber value. NOTE: the vendor states "the information that is being queried is authorized for an authenticated user of that application, so we consider this not applicable.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Accela ≫ Civic Platform Version <= 20.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 6.77% | 0.909 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|