Priority Portal Generator是以色列Priority公司的一款企业资源计划系统的附加组件。 Priority Portal Generator v3版本存在授权问题漏洞,该漏洞源于关键功能缺少身份验证,可能导致未经身份验证的攻击者通过网络访问获取敏感数据或修改数据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Priority | Portal Generator addon to Priority ERP (developed by Soft Solutions) | All versions without Priwall v3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Priority | Portal Generator addon to Priority ERP (developed by Soft Solutions) | All versions without Priwall v3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59500 | 10.0 CRITICAL | Priority - CWE-287: Improper Authentication |
| CVE-2026-59507 | 9.3 CRITICAL | Priority – CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Informa |
| CVE-2026-59503 | 9.1 CRITICAL | Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: E |
| CVE-2026-59504 | 9.1 CRITICAL | Priority – CWE-602: Client-Side Enforcement of Server-Side Security |
| CVE-2026-59499 | 8.6 HIGH | Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor |
| CVE-2026-59505 | 8.6 HIGH | Priority - CWE-284: Improper Access Control |
| CVE-2026-59501 | 8.2 HIGH | Priority – CWE-284: Improper Access Control |
| CVE-2026-59502 | 5.3 MEDIUM | Priority - CWE-203: Observable Discrepancy |
No comments yet