Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3rrq-p5gv-7828

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Poor cryptographic salt initialization in admin/inc/template_functions.php in GetSimple CMS 3.3.13 allows a network attacker to escalate privileges to an arbitrary user or conduct CSRF attacks via calculation of a session cookie or CSRF nonce.

Poor cryptographic salt initialization in admin/inc/template_functions.php in GetSimple CMS 3.3.13 allows a network attacker to escalate privileges to an arbitrary user or conduct CSRF attacks via calculation of a session cookie or CSRF nonce.

EPSS

Процентиль: 57%
0.00351
Низкий

8.8 High

CVSS3

Дефекты

CWE-338

Связанные уязвимости

CVSS3: 8.8
nvd
почти 9 лет назад

Poor cryptographic salt initialization in admin/inc/template_functions.php in GetSimple CMS 3.3.13 allows a network attacker to escalate privileges to an arbitrary user or conduct CSRF attacks via calculation of a session cookie or CSRF nonce.

EPSS

Процентиль: 57%
0.00351
Низкий

8.8 High

CVSS3

Дефекты

CWE-338