5.3
CVE-2022-40292
- EPSS 0.26%
- Veröffentlicht 31.10.2022 21:15:13
- Zuletzt bearbeitet 06.05.2025 20:15:24
- Quelle vdp@themissinglink.com.au
- CVE-Watchlists
- Unerledigt
The application allowed for Unauthenticated User Enumeration by interacting with an unsecured endpoint to retrieve information on each account within the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Phppointofsale ≫ Php Point Of Sale Version19.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.26% | 0.492 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-209 Generation of Error Message Containing Sensitive Information
The product generates an error message that includes sensitive information about its environment, users, or associated data.