Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6cq5-38vf-h3g2

Опубликовано: 10 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.2

Описание

Cross Site Request Forgery vulnerability in in the upload functionality of the User Profile pages in savignano S/Notify before 2.0.1 for Bitbucket allow attackers to replace S/MIME certificate or PGP keys for arbitrary users via crafted link.

Cross Site Request Forgery vulnerability in in the upload functionality of the User Profile pages in savignano S/Notify before 2.0.1 for Bitbucket allow attackers to replace S/MIME certificate or PGP keys for arbitrary users via crafted link.

EPSS

Процентиль: 38%
0.00169
Низкий

5.2 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 5.2
nvd
почти 2 года назад

Cross Site Request Forgery vulnerability in in the upload functionality of the User Profile pages in savignano S/Notify before 2.0.1 for Bitbucket allow attackers to replace S/MIME certificate or PGP keys for arbitrary users via crafted link.

EPSS

Процентиль: 38%
0.00169
Низкий

5.2 Medium

CVSS3

Дефекты

CWE-352