XSS Hunter Express before 2021-09-17 does not properly enforce authentication requirements for paths.
{
"unresolved_ranges": [
{
"vendor_product": "xss_hunter_express_project:xss_hunter_express",
"extracted_events": [
{
"fixed": "2021-09-17"
}
],
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:xss_hunter_express_project:xss_hunter_express:*:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"fixed": "2021-09-17"
}
],
"source": "DESCRIPTION"
}
]
}