Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
U.S. GAO EPDS and CBCA EDS unauthenticated password change
Vulnerability Description
The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) does not authenticate password change requests to the '/update-profile/N' API endpoint. A remote, unauthenticated attacker could change an arbitrary user's password.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
关键功能的认证机制缺失
Vulnerability Title
Government Accountability Office Electronic Protest Docketing System 授权问题漏洞
Vulnerability Description
Government Accountability Office Electronic Protest Docketing System是美国Government Accountability Office政府部门的一个电子抗议登记系统,主要用于在线提交、管理和跟踪针对美国联邦政府采购合同的异议及抗议案件。 Government Accountability Office Electronic Protest Docketing System存在授权问题漏洞,该漏洞源于对'/update-profile/
CVSS Information
N/A
Vulnerability Type
N/A