A CWE-306: Missing Authentication for Critical Function...
Critical severity
Unreviewed
Published
Jan 31, 2023
to the GitHub Advisory Database
•
Updated May 25, 2023
Description
Published by the National Vulnerability Database
Jan 30, 2023
Published to the GitHub Advisory Database
Jan 31, 2023
Last updated
May 25, 2023
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause access to manipulate and read files in the IGSS project report directory when an attacker sends specific messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22170)
References