漏洞标题
Control iD RH iD PDF Document companyId 注入漏洞
漏洞描述信息
在Control iD RH iD 25.2.25.0中发现了一个漏洞,并被归类为有问题的漏洞。该漏洞影响组件PDF文档处理器中的文件/v2/report.svc/comprovante_marcacao/?companyId=1的未知代码。参数nsr的操纵会导致资源标识符的控制不当。攻击可以远程发起。厂商在披露初期被联系,但没有做出任何回应。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
漏洞类别
不加限制或调节的资源分配
漏洞标题
Control iD RH iD PDF Document companyId resource injection
漏洞描述信息
A vulnerability has been found in Control iD RH iD 25.2.25.0 and classified as problematic. This vulnerability affects unknown code of the file /v2/report.svc/comprovante_marcacao/?companyId=1 of the component PDF Document Handler. The manipulation of the argument nsr leads to improper control of resource identifiers. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
漏洞类别
对资源描述符的控制不恰当(资源注入)