Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-79w3-7qxh-q2r4

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any user/admin, to escalate privileges, and to gain access to more data and functionality. This issue exists due to the lack of a requirement to provide the old password, and the lack of security tokens.

An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any user/admin, to escalate privileges, and to gain access to more data and functionality. This issue exists due to the lack of a requirement to provide the old password, and the lack of security tokens.

EPSS

Процентиль: 72%
0.00718
Низкий

Связанные уязвимости

CVSS3: 8.8
nvd
почти 6 лет назад

An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any user/admin, to escalate privileges, and to gain access to more data and functionality. This issue exists due to the lack of a requirement to provide the old password, and the lack of security tokens.

CVSS3: 8.8
debian
почти 6 лет назад

An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4 ...

EPSS

Процентиль: 72%
0.00718
Низкий