Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3q67-fwp6-mgfc

Опубликовано: 02 дек. 2021
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via the name field in my-profile.php. Chaining to this both vulnerabilities leads to account takeover.

Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via the name field in my-profile.php. Chaining to this both vulnerabilities leads to account takeover.

EPSS

Процентиль: 34%
0.00135
Низкий

8.8 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
nvd
около 4 лет назад

Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via the name field in my-profile.php. Chaining to this both vulnerabilities leads to account takeover.

EPSS

Процентиль: 34%
0.00135
Низкий

8.8 High

CVSS3

Дефекты

CWE-352