Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9wj3-35xv-c6hq

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

3scale dev portal login form does not verify CSRF token, and so does not protect against login CSRF.

3scale dev portal login form does not verify CSRF token, and so does not protect against login CSRF.

EPSS

Процентиль: 53%
0.00301
Низкий

8.8 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 5.4
redhat
больше 5 лет назад

A vulnerability was found that the 3scale dev portal does not employ mechanisms for protection against login CSRF. An attacker could use this flaw to access unauthorized information or conduct further attacks.

CVSS3: 8.8
nvd
больше 4 лет назад

A vulnerability was found that the 3scale dev portal does not employ mechanisms for protection against login CSRF. An attacker could use this flaw to access unauthorized information or conduct further attacks.

EPSS

Процентиль: 53%
0.00301
Низкий

8.8 High

CVSS3

Дефекты

CWE-352