Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5r7h-75x2-554g

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Various resources in the Crowd Demo application of Atlassian Crowd before version 3.1.1 allow remote attackers to modify add, modify and delete users & groups via a Cross-site request forgery (CSRF) vulnerability. Please be aware that the Demo application is not enabled by default.

Various resources in the Crowd Demo application of Atlassian Crowd before version 3.1.1 allow remote attackers to modify add, modify and delete users & groups via a Cross-site request forgery (CSRF) vulnerability. Please be aware that the Demo application is not enabled by default.

EPSS

Процентиль: 61%
0.00411
Низкий

Связанные уязвимости

CVSS3: 6.5
nvd
около 6 лет назад

Various resources in the Crowd Demo application of Atlassian Crowd before version 3.1.1 allow remote attackers to modify add, modify and delete users & groups via a Cross-site request forgery (CSRF) vulnerability. Please be aware that the Demo application is not enabled by default.

EPSS

Процентиль: 61%
0.00411
Низкий