Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fmgv-rqvg-5pqf

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

GeniXCMS 1.1.7 is vulnerable to user privilege escalation due to broken access control. This issue exists because of an incomplete fix for CVE-2015-2680, in which "token" is used as a CSRF protection mechanism, but without validation that "token" is associated with an administrative user.

GeniXCMS 1.1.7 is vulnerable to user privilege escalation due to broken access control. This issue exists because of an incomplete fix for CVE-2015-2680, in which "token" is used as a CSRF protection mechanism, but without validation that "token" is associated with an administrative user.

EPSS

Процентиль: 39%
0.00177
Низкий

Связанные уязвимости

CVSS3: 8.8
nvd
почти 6 лет назад

GeniXCMS 1.1.7 is vulnerable to user privilege escalation due to broken access control. This issue exists because of an incomplete fix for CVE-2015-2680, in which "token" is used as a CSRF protection mechanism, but without validation that "token" is associated with an administrative user.

EPSS

Процентиль: 39%
0.00177
Низкий