6.5

CVE-2021-45478

IDOR in Yordam Library Automation System

Improper Handling of Parameters vulnerability in Bordam Information Technologies Library Automation System allows Collect Data as Provided by Users.

This issue affects Library Automation System: before 19.2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
YordamLibrary Automation System Version < 19.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.59% 0.433
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
iletisim@usom.gov.tr 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-233 Improper Handling of Parameters

The product does not properly handle when the expected number of parameters, fields, or arguments is not provided in input, or if those parameters are undefined.

https://www.usom.gov.tr/bildirim/tr-23-0119
Third Party Advisory
https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-23-0119