CVE-2020-10778 Vulnerability Details
/
/
/
CVE-2020-10778 Metadata Quick Info
CVE Published: 11/08/2020 |
CVE Updated: 04/08/2024 |
CVE Year: 2020
Source: redhat |
Vendor: n/a |
Product: CloudForms
Status : PUBLISHED
CVE-2020-10778 Description
In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled attribute from the fields since there is no server-side validation. This business logic flaw violate the expected behavior.
Metrics
CVSS Version: 3.1 |
Base Score: n/a
Vector: n/a
l➤ Exploitability Metrics:
Attack Vector (AV)*
Attack Complexity (AC)*
Privileges Required (PR)*
User Interaction (UI)*
Scope (S)*
l➤ Impact Metrics:
Confidentiality Impact (C)*
Integrity Impact (I)*
Availability Impact (A)*
Weakness Enumeration (CWE)
CWE-ID:
CWE Name: Incorrect Authorization
Source: n/a
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID:
CAPEC Description:
Source: NVD (National Vulnerability Database).