Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6jfg-4px6-v4c9

Опубликовано: 04 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.1 and below that may in some cases allow a remote, unauthenticated attacker to trick an authorized user into executing unwanted actions via a crafted form. The impact to Confidentiality and Integrity vectors is limited and of low severity. 

There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.1 and below that may in some cases allow a remote, unauthenticated attacker to trick an authorized user into executing unwanted actions via a crafted form. The impact to Confidentiality and Integrity vectors is limited and of low severity. 

EPSS

Процентиль: 51%
0.00281
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 5.4
nvd
почти 2 года назад

There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.1 and below that may in some cases allow a remote, unauthenticated attacker to trick an authorized user into executing unwanted actions via a crafted form. The impact to Confidentiality and Integrity vectors is limited and of low severity.

EPSS

Процентиль: 51%
0.00281
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-352