CVE-2021-36723
6.1MEDIUMEmuse - eServices / eNvoice Exposure Of Private Personal Information due to lack of identification mechanisms and predictable IDs an attacker can scrape all the files on the service.
Published: 12/29/2021Updated: 11/21/2024
Description
Emuse - eServices / eNvoice Exposure Of Private Personal Information due to lack of identification mechanisms and predictable IDs an attacker can scrape all the files on the service.
AI AnalysisPowered by AI
Affected Products
emuse_-_eservices_\/_envoice_projectemuse_-_eservices_\/_envoice
-
References
- https://www.gov.il/en/departments/faq/cve_advisoriesThird Party Advisory
- https://www.gov.il/en/departments/faq/cve_advisoriesThird Party Advisory