CVE-2019-12837

MEDIUM

Gencat Portal D'acces A LA Universitat - Incorrect Authorization

Title source: rule
STIX 2.1

Description

The Java API in accesuniversitat.gencat.cat 1.7.5 allows remote attackers to get personal information of all registered students via several API endpoints.

Scores

CVSS v3 4.3
EPSS 0.0022
EPSS Percentile 44.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-706 CWE-863
Status published
Products (1)
gencat/portal_d\'acces_a_la_universitat 1.7.5
Published Dec 31, 2019
Tracked Since Feb 18, 2026