Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:34115
HistoryFeb 09, 2022 - 7:25 a.m.

Business Logic Errors

2022-02-0907:25:40
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4
publify_core
vulnerability
update_params
password field
attacker exploit

EPSS

0.002

Percentile

53.5%

publify_core is vulnerable to business logic errors. The vulnerability exists in update_params function of content_controller.rb because the password field present in the form is not accepted by the controller which allows an attacker to exploit this flaw since the article is always public.

EPSS

0.002

Percentile

53.5%