3.7

CVE-2023-38872

Exploit
An Insecure Direct Object Reference (IDOR) vulnerability in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1 allows any unauthenticated attacker to access cash book entry attachments of any other user, if they know the Id of the attachment.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
EconomizzerEconomizzer Version0.9 Updatebeta1 SwPlatformwordpress
EconomizzerEconomizzer Versionapril_2023 SwPlatformwordpress
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.6% 0.439
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 3.7 2.2 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-639 Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

https://github.com/gugoan/economizzer
Product
https://www.economizzer.org
Product
https://github.com/dub-flow/vulnerability-research/tree/main/CVE-2023-38872
Third Party Advisory
Exploit