Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:44585
HistoryDec 06, 2023 - 1:50 p.m.

Information Disclosure

2023-12-0613:50:21
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7
microsoft-graph
information disclosure
getphpinfo.php
configuration details
modules
environment variables
web accessible
vendor directory

5.4 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

45.5%

microsoft/microsoft-graph is vulnerable to Information Disclosure. The vulnerability exists in the phpinfo function of GetPhpInfo.php, allowing an attacker to access unauthorized system information such as configuration details, modules, and environment variables. This vulnerability is only exploitable if the applications /vendor directory is web accessible.

5.4 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

45.5%