ZeroHour

CVE-2021-42330

CVSS 3.1
8.8 high
EPSS
<1%p60
Published
()
Modified
Description

The “Teacher Edit” function of ShinHer StudyOnline System does not perform authority control. After logging in with user’s privilege, remote attackers can access and edit other users’ credential and personal information by crafting URL parameters.

Vendors
xinheinformation
Products
xinhe teaching platform system
Weakness
CWE-285
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.