Vulnerabilities
Vulnerable Software
B1ackc4t:  >> 14finger  >> 1.1  Security Vulnerabilities
14Finger v1.1 was discovered to contain a remote command execution (RCE) vulnerability in the fingerprint function. This vulnerability allows attackers to execute arbitrary commands via a crafted payload.
CVSS Score
9.1
EPSS Score
0.111
Published
2024-07-10
Insecure permissions in the component /api/admin/user of 14Finger v1.1 allows attackers to access all user information via a crafted GET request.
CVSS Score
7.5
EPSS Score
0.001
Published
2024-07-05
14Finger v1.1 was discovered to contain an arbitrary user deletion vulnerability via the component /api/admin/user?id.
CVSS Score
9.1
EPSS Score
0.002
Published
2024-07-05
Insecure permissions in 14Finger v1.1 allow attackers to escalate privileges from normal user to Administrator via a crafted POST request.
CVSS Score
8.8
EPSS Score
0.001
Published
2024-07-05


Contact Us

Shodan ® - All rights reserved