CVE-2021-36723
MEDIUMEmuse - Eservices / Envoice - Information Disclosure
Title source: ruleDescription
Emuse - eServices / eNvoice Exposure Of Private Personal Information due to lack of identification mechanisms and predictable IDs an attacker can scrape all the files on the service.
Scores
CVSS v3
6.1
EPSS
0.0021
EPSS Percentile
43.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Details
CWE
CWE-359
CWE-200
Status
published
Products (1)
emuse_-_eservices_\/_envoice_project/emuse_-_eservices_\/_envoice
Published
Dec 29, 2021
Tracked Since
Feb 18, 2026