Showing 3 vulnerabilities on this page for 14finger

Signals CISA KEV Ransomware Nuclei
b1ackc4t vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

14Finger v1.1 was discovered to contain a remote command execution (RCE) vulnerability in the fingerprint function. This vulnerability allows attackers to execute arbitrary commands via a crafted payload.

CWE-94Jul 10, 2024
CVSS9.1v3.1EPSS1.57%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Insecure permissions in 14Finger v1.1 allow attackers to escalate privileges from normal user to Administrator via a crafted POST request.

CWE-278Jul 5, 2024
CVSS8.8v3.1EPSS0.459%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Insecure permissions in the component /api/admin/user of 14Finger v1.1 allows attackers to access all user information via a crafted GET request.

CWE-306Jul 5, 2024
CVSS7.5v3.1EPSS0.396%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX