CVSS v3.1 reference card

CVE-2024-XXXXX (this lab) — Unauthenticated POST to /api/v1/admin/export reads any file as root. No UI required, scope unchanged. Score it.

Metrics

AV — Attack VectorN=Network, A=Adjacent (same broadcast), L=Local, P=Physical
AC — Attack ComplexityL=Low, H=High (requires specialized conditions)
PR — Privileges RequiredN=None, L=Low (user account), H=High (admin)
UI — User InteractionN=None, R=Required (e.g. click a link)
S — ScopeU=Unchanged, C=Changed (vuln breaks out of vuln component's privilege boundary)
C — ConfidentialityH=High, L=Low, N=None
I — IntegrityH/L/N
A — AvailabilityH/L/N

Score bands

0.1–3.9Low
4.0–6.9Medium
7.0–8.9High
9.0–10.0Critical

Use cvss.techclick.in for a live calculator if you need to verify your arithmetic.