Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-37214
HistoryAug 09, 2021 - 10:15 a.m.

Command injection

2021-08-0910:15:00
PRIOn knowledge base
www.prio-n.com
4

8.8 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

69.4%

The employee management page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the employee ID in specific parameters to arbitrary access employee’s data, modify it, and then obtain administrator privilege and execute arbitrary command.

CPENameOperatorVersion
flygolt1.91.1

8.8 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

69.4%

Related for PRION:CVE-2021-37214