Systemic Risk Value <=2.8.0 is vulnerable to improper...
Moderate severity
Unreviewed
Published
Mar 18, 2025
to the GitHub Advisory Database
•
Updated Mar 25, 2025
Description
Published by the National Vulnerability Database
Mar 18, 2025
Published to the GitHub Advisory Database
Mar 18, 2025
Last updated
Mar 25, 2025
Systemic Risk Value <=2.8.0 is vulnerable to improper access control in /RiskValue/GroupingEntities/Controls/GetFile.aspx?ID=. Uploaded files are accessible via a predictable numerical ID parameter, allowing unauthorized users to increment or decrement the ID to access and download files they do not have permission to view.
References