Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2xfw-9v88-vhpx

Опубликовано: 15 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 5.3

Описание

Arunna 1.0.0 contains a cross-site request forgery vulnerability that allows attackers to manipulate user profile settings without authentication. Attackers can craft a malicious form to change user details, including passwords, email, and administrative privileges by tricking authenticated users into submitting the form.

Arunna 1.0.0 contains a cross-site request forgery vulnerability that allows attackers to manipulate user profile settings without authentication. Attackers can craft a malicious form to change user details, including passwords, email, and administrative privileges by tricking authenticated users into submitting the form.

EPSS

Процентиль: 1%
0.00012
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 6.5
nvd
24 дня назад

Arunna 1.0.0 contains a cross-site request forgery vulnerability that allows attackers to manipulate user profile settings without authentication. Attackers can craft a malicious form to change user details, including passwords, email, and administrative privileges by tricking authenticated users into submitting the form.

EPSS

Процентиль: 1%
0.00012
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-352