Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-85f4-3cvc-fmrq

Опубликовано: 22 мая 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.4

Описание

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12. The vulnerability exists in /admin/DatabaseQuery, which allows an attacker to manipulate a victim with administrative privileges to execute arbitrary SQL commands.

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12. The vulnerability exists in /admin/DatabaseQuery, which allows an attacker to manipulate a victim with administrative privileges to execute arbitrary SQL commands.

EPSS

Процентиль: 39%
0.00177
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 6.4
nvd
больше 1 года назад

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12. The vulnerability exists in /admin/DatabaseQuery, which allows an attacker to manipulate a victim with administrative privileges to execute arbitrary SQL commands.

EPSS

Процентиль: 39%
0.00177
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-352