Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-642x-cgp3-jphq

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not sign all required data in requests, which has unspecified impact, probably related to man-in-the-middle attacks that modify critical data and allow remote attackers to impersonate other users and gain privileges.

Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not sign all required data in requests, which has unspecified impact, probably related to man-in-the-middle attacks that modify critical data and allow remote attackers to impersonate other users and gain privileges.

EPSS

Процентиль: 71%
0.00697
Низкий

Связанные уязвимости

nvd
почти 16 лет назад

Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not sign all required data in requests, which has unspecified impact, probably related to man-in-the-middle attacks that modify critical data and allow remote attackers to impersonate other users and gain privileges.

EPSS

Процентиль: 71%
0.00697
Низкий