CVE-2021-36723

MEDIUM

Emuse - Eservices / Envoice - Information Disclosure

Title source: rule
STIX 2.1

Description

Emuse - eServices / eNvoice Exposure Of Private Personal Information due to lack of identification mechanisms and predictable IDs an attacker can scrape all the files on the service.

Scores

CVSS v3 6.1
EPSS 0.0021
EPSS Percentile 43.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N

Details

CWE
CWE-359 CWE-200
Status published
Products (1)
emuse_-_eservices_\/_envoice_project/emuse_-_eservices_\/_envoice
Published Dec 29, 2021
Tracked Since Feb 18, 2026