ZeroHour

CVE-2021-28174

CVSS 3.1
6.5 medium
EPSS
<1%p59
Published
()
Modified
Description

Mitake smart stock selection system contains a broken authentication vulnerability. By manipulating the parameters in the URL, remote attackers can gain the privileged permissions to access transaction record, and fraudulent trading without login.

Vendors
mitake
Products
smart stock selection
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.