Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-25m7-6389-m7rq

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

IBM Security Verify Information Queue 1.0.6 and 1.0.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

IBM Security Verify Information Queue 1.0.6 and 1.0.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

EPSS

Процентиль: 30%
0.00109
Низкий

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
nvd
больше 4 лет назад

IBM Security Verify Information Queue 1.0.6 and 1.0.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

EPSS

Процентиль: 30%
0.00109
Низкий

Дефекты

CWE-352