Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9r2w-p922-mx3m

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Multiple cross-site request forgery (CSRF) vulnerabilities in (1) addaddress.php, (2) toggleignore.php, (3) removeignore.php, and (4) removeaddress.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to modify settings as another user via a link or IMG tag.

Multiple cross-site request forgery (CSRF) vulnerabilities in (1) addaddress.php, (2) toggleignore.php, (3) removeignore.php, and (4) removeaddress.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to modify settings as another user via a link or IMG tag.

EPSS

Процентиль: 55%
0.00325
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 6.5
nvd
больше 20 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in (1) addaddress.php, (2) toggleignore.php, (3) removeignore.php, and (4) removeaddress.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to modify settings as another user via a link or IMG tag.

EPSS

Процентиль: 55%
0.00325
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-352