Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3fq7-mmjq-fv4x

Опубликовано: 03 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

CandidATS version 3.0.0 allows an external attacker to elevate privileges in the application. This is possible because the application suffers from CSRF. This allows to persuade an administrator to create a new account with administrative permissions.

CandidATS version 3.0.0 allows an external attacker to elevate privileges in the application. This is possible because the application suffers from CSRF. This allows to persuade an administrator to create a new account with administrative permissions.

EPSS

Процентиль: 23%
0.00078
Низкий

8.8 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
nvd
больше 3 лет назад

CandidATS version 3.0.0 allows an external attacker to elevate privileges in the application. This is possible because the application suffers from CSRF. This allows to persuade an administrator to create a new account with administrative permissions.

EPSS

Процентиль: 23%
0.00078
Низкий

8.8 High

CVSS3

Дефекты

CWE-352