SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-42330

After logging in with user’s privilege, remote attackers can access and edit other users’ credential and personal information by crafting URL parameters.

HIGH 8.8EPSS 0.98%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.98%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The “Teacher Edit” function of ShinHer StudyOnline System does not perform authority control. After logging in with user’s privilege, remote attackers can access and edit other users’ credential and personal information by crafting URL parameters.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.98% probability · 60th percentile
CISA KEV
Not listed
Weakness
CWE-285
Affected
xinheinformation/xinhe teaching platform system
Source
twcert@cert.org.tw

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.