Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6xx3-7c4w-v79g

Опубликовано: 15 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

glFusion CMS 1.7.9 is affected by a Cross Site Request Forgery (CSRF) vulnerability in /public_html/admin/plugins/bad_behavior2/blacklist.php. Using the CSRF vulnerability to trick the administrator to click, an attacker can add a blacklist.

glFusion CMS 1.7.9 is affected by a Cross Site Request Forgery (CSRF) vulnerability in /public_html/admin/plugins/bad_behavior2/blacklist.php. Using the CSRF vulnerability to trick the administrator to click, an attacker can add a blacklist.

EPSS

Процентиль: 27%
0.00098
Низкий

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 4.3
nvd
около 4 лет назад

glFusion CMS 1.7.9 is affected by a Cross Site Request Forgery (CSRF) vulnerability in /public_html/admin/plugins/bad_behavior2/blacklist.php. Using the CSRF vulnerability to trick the administrator to click, an attacker can add a blacklist.

EPSS

Процентиль: 27%
0.00098
Низкий

Дефекты

CWE-352