7.5
CVSSv3

CVE-2022-28607

Published: 01/12/2022 Updated: 05/12/2022
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue exists in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows malicious users to gain sensitive information via the action parameter to /system/user/modules/mod_users/controller.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

isic.lk project isic.lk