David-Crty databasement Snapshot Model snapshots SnapshotPolicy.view access control
30Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 5.3
probabilidad de explotación
—
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
A vulnerability was determined in David-Crty databasement up to 1.7.1. Affected is the function SnapshotPolicy.viewAny/SnapshotPolicy.view of the file /api/v1/snapshots of the component Snapshot Model. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.7.2 is able to address this issue. The affected component should be upgraded.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Productos afectados
David-Crty · databasementPoCs públicas encontradas — 1
cve_referencegithub.com/David-Crty/databasement/security/advisories/GHSA-vx6q-v2gv-5fhvno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
https://github.com/David-Crty/databasement/https://github.com/David-Crty/databasement/releases/tag/v1.7.2https://github.com/David-Crty/databasement/security/advisories/GHSA-vx6q-v2gv-5fhvhttps://vuldb.com/cve/CVE-2026-103534https://vuldb.com/submit/957818https://vuldb.com/vuln/412346https://vuldb.com/vuln/412346/cti