Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9vgq-8h3w-xj2r

Опубликовано: 26 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.3

Описание

A Cross-Site Request Forgery (CSRF) vulnerability exists in kishan0725's Hospital Management System version 6.3.5. The vulnerability allows an attacker to craft a malicious HTML form that submits a request to delete a doctor record. By enticing an authenticated admin user to visit the specially crafted web page, the attacker can leverage the victim's browser to make unauthorized requests to the vulnerable endpoint, effectively allowing the attacker to perform actions on behalf of the admin without their consent.

A Cross-Site Request Forgery (CSRF) vulnerability exists in kishan0725's Hospital Management System version 6.3.5. The vulnerability allows an attacker to craft a malicious HTML form that submits a request to delete a doctor record. By enticing an authenticated admin user to visit the specially crafted web page, the attacker can leverage the victim's browser to make unauthorized requests to the vulnerable endpoint, effectively allowing the attacker to perform actions on behalf of the admin without their consent.

EPSS

Процентиль: 33%
0.00131
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 6.3
nvd
больше 1 года назад

A Cross-Site Request Forgery (CSRF) vulnerability exists in kishan0725's Hospital Management System version 6.3.5. The vulnerability allows an attacker to craft a malicious HTML form that submits a request to delete a doctor record. By enticing an authenticated admin user to visit the specially crafted web page, the attacker can leverage the victim's browser to make unauthorized requests to the vulnerable endpoint, effectively allowing the attacker to perform actions on behalf of the admin without their consent.

EPSS

Процентиль: 33%
0.00131
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-352