Insecure service configuration - Business logic
Description
Weaknesses in business logic become apparent in the design and implementation of an application, allowing an attacker to trigger unwanted behavior. an attacker to trigger unwanted behavior. This opens the possibility for attackers to manipulate legitimate functions in order to perform malicious actions. legitimate functions in order to perform malicious actions.
Impact
- Change system functionality or user data of the affected service. - Gain access to sensitive data and functions.
Recommendation
Ensure that the functionalities provided are clear in both design and operation and that the flows fulfill their specific function.
Threat
Authenticated attacker with access to the service from the Internet.
Expected Remediation Time
⌚ 2400 minutes.
Score
Default score using CVSS 3.1. It may change depending on the context of the src.
Base
- Attack vector: N
- Attack complexity: L
- Privileges required: L
- User interaction: N
- Scope: U
- Confidentiality: L
- Integrity: L
- Availability: N
Temporal
- Exploit code maturity: P
- Remediation level: U
- Report confidence: C
Result
- Vector string: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N/E:P/RL:U/RC:C
- Score:
- Severity:
- Base: Medium
- Temporal: Medium
Score 4.0
Default score using CVSS 4.0. It may change depending on the context of the src.
Base 4.0
- Attack vector: N
- Attack complexity: L
- Attack Requirements: N
- Privileges required: L
- User interaction: N
- Confidentiality (VC): L
- Integrity (VI): L
- Availability (VA): N
- Confidentiality (SC): N
- Integrity (SI): N
- Availability (SA): N
Threat 4.0
Result 4.0
- Vector string: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
- Score:
- Severity:
Compliant code
Non compliant code
Requirements
Fixes
Free trial