Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4jqx-c8xq-4m8x

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Cross-site request forgery (CSRF) vulnerability in administration/profiles.php in Dolphin 7.1.4 and earlier allows remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the members[] parameter, related to CVE-2014-3810.

Cross-site request forgery (CSRF) vulnerability in administration/profiles.php in Dolphin 7.1.4 and earlier allows remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the members[] parameter, related to CVE-2014-3810.

EPSS

Процентиль: 44%
0.00216
Низкий

Дефекты

CWE-352

Связанные уязвимости

nvd
больше 11 лет назад

Cross-site request forgery (CSRF) vulnerability in administration/profiles.php in Dolphin 7.1.4 and earlier allows remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the members[] parameter, related to CVE-2014-3810.

EPSS

Процентиль: 44%
0.00216
Низкий

Дефекты

CWE-352