Nebula Informatics SecHard Authorization Bypass Vulnerability Allowing Parameter Injection
Vulnerability
A vulnerability allowing authorization bypass through user-controlled keys has been identified in Nebula Informatics SecHard versions prior to 3.6.2-20250805. This issue, which requires low privileges, enables parameter injection, potentially allowing attackers to manipulate application behavior or data.
Impact
Exploitation of this vulnerability could lead to unauthorized actions being performed on behalf of a user, potentially allowing for further attacks or manipulation of application data.
Remediation
Users and system administrators are advised to upgrade to SecHard version 3.6.2-20250805 or later.
Added: Sep 17, 2025, 1:20 PM
Updated: Sep 17, 2025, 2:28 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
1.3exploitability
5.2remediation
7.7relevance
0.5threat
0.0urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
