From 28bf4b3383552edbe26dccfc76dcb0b4c3c0227e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 3 Oct 2023 21:14:52 +0000 Subject: [PATCH] Publish GHSA-896v-ph5w-379h --- .../09/GHSA-896v-ph5w-379h/GHSA-896v-ph5w-379h.json | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/advisories/github-reviewed/2023/09/GHSA-896v-ph5w-379h/GHSA-896v-ph5w-379h.json b/advisories/github-reviewed/2023/09/GHSA-896v-ph5w-379h/GHSA-896v-ph5w-379h.json index a5f453df61b..a82990aa4f6 100644 --- a/advisories/github-reviewed/2023/09/GHSA-896v-ph5w-379h/GHSA-896v-ph5w-379h.json +++ b/advisories/github-reviewed/2023/09/GHSA-896v-ph5w-379h/GHSA-896v-ph5w-379h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-896v-ph5w-379h", - "modified": "2023-09-28T16:49:40Z", + "modified": "2023-10-03T21:13:36Z", "published": "2023-09-28T06:30:20Z", "aliases": [ "CVE-2023-38872" @@ -9,7 +9,10 @@ "summary": "Economizzer Insecure Direct Object Reference vulnerability", "details": "An Insecure Direct Object Reference (IDOR) vulnerability in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1 allows any unauthenticated attacker to access cash book entry attachments of any other user, if they know the Id of the attachment.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ { @@ -61,9 +64,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-639" ], - "severity": "MODERATE", + "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2023-09-28T16:49:40Z", "nvd_published_at": null