Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cr4r-2wf7-9633

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Fivestar module 6.x-1.x before 6.x-1.20 for Drupal does not properly validate voting data, which allows remote attackers to manipulate voting averages via a negative value in the vote parameter.

The Fivestar module 6.x-1.x before 6.x-1.20 for Drupal does not properly validate voting data, which allows remote attackers to manipulate voting averages via a negative value in the vote parameter.

EPSS

Процентиль: 59%
0.00391
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
почти 13 лет назад

The Fivestar module 6.x-1.x before 6.x-1.20 for Drupal does not properly validate voting data, which allows remote attackers to manipulate voting averages via a negative value in the vote parameter.

EPSS

Процентиль: 59%
0.00391
Низкий

Дефекты

CWE-20