4.3
CVE-2024-49373
- EPSS 0.42%
- Veröffentlicht 22.10.2024 16:15:08
- Zuletzt bearbeitet 30.10.2024 21:16:59
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
No Fuss Computing Centurion ERP is open source enterprise resource planning (ERP) software. Prior to version 1.2.1, an authenticated user can view projects within organizations they are not apart of. Version 1.2.1 fixes the problem.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nofusscomputing ≫ Centurion Erp Version < 1.2.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.42% | 0.612 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
| security-advisories@github.com | 4.1 | 0.5 | 3.6 |
CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
|
CWE-653 Improper Isolation or Compartmentalization
The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.