Nebula Informatics SecHard Authorization Bypass Vulnerability Allowing Parameter Injection

Vulnerability

A vulnerability allowing authorization bypass through user-controlled keys has been identified in Nebula Informatics SecHard versions prior to 3.6.2-20250805. This issue, which requires low privileges, enables parameter injection, potentially allowing attackers to manipulate application behavior or data.

Impact

Exploitation of this vulnerability could lead to unauthorized actions being performed on behalf of a user, potentially allowing for further attacks or manipulation of application data.

Remediation

Users and system administrators are advised to upgrade to SecHard version 3.6.2-20250805 or later.

Added: Sep 17, 2025, 1:20 PM
Updated: Sep 17, 2025, 2:28 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
5.2
remediation
7.7
relevance
0.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.