Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:26283
HistoryAug 07, 2020 - 2:30 a.m.

Authorization Bypass

2020-08-0702:30:39
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.001 Low

EPSS

Percentile

27.7%

cfme is vulnerable to authorization bypass. The read-only widgets can be edited by inspecting the forms and dropping the disabled attribute from the fields since there is no server-side validation. This business logic flaw violates the expected behavior.

0.001 Low

EPSS

Percentile

27.7%