Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fcw5-4759-g9vf

Опубликовано: 07 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intentionally. An attacker can cause a victim's browser to emit an HTTP request to an arbitrary URL in the application.

This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intentionally. An attacker can cause a victim's browser to emit an HTTP request to an arbitrary URL in the application.

EPSS

Процентиль: 28%
0.00102
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 2.3
nvd
почти 4 года назад

This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intentionally. An attacker can cause a victim's browser to emit an HTTP request to an arbitrary URL in the application.

EPSS

Процентиль: 28%
0.00102
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-345