3.7
CVE-2023-38872
- EPSS 0.3%
- Veröffentlicht 28.09.2023 04:15:12
- Zuletzt bearbeitet 21.11.2024 08:14:20
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An Insecure Direct Object Reference (IDOR) vulnerability in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1 allows any unauthenticated attacker to access cash book entry attachments of any other user, if they know the Id of the attachment.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Economizzer ≫ Economizzer Version0.9 Updatebeta1 SwPlatformwordpress
Economizzer ≫ Economizzer Versionapril_2023 SwPlatformwordpress
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.3% | 0.527 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 3.7 | 2.2 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-639 Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.