Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Camden Jace Powell

#21038of 53,779
11.8Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2021-20368
4.3
2021-09-08
Unknown · Fish | Hunt Fl · CVE-2021-33981
Name of the Vulnerable Software and Affected Versions: Fish | Hunt FL versions 3.8.0 and earlier Description: The issue concerns an insecure, direct object vulnerability in the hunting/fishing license retrieval function. This allows a remote authenticated attacker to retrieve other people's personal information and images of their hunting/fishing licenses. Recommendations: For versions 3.8.0 and earlier, update to a version later than 3.8.0 to resolve the issue. As a temporary workaround, consider restricting access to the hunting/fishing license retrieval function until a patch is available.
PT-2021-20369
7.5
2021-09-08
Unknown · Fish | Hunt Fl · CVE-2021-33982
Name of the Vulnerable Software and Affected Versions: Fish | Hunt FL versions 3.8.0 and earlier Description: An insufficient session expiration issue exists, allowing a remote attacker to reuse, spoof, or steal other user and admin sessions. Recommendations: For versions 3.8.0 and earlier, update to a version later than 3.8.0 to resolve the issue. As a temporary workaround, consider restricting access to sensitive features that rely on session authentication until a patch is available.