Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fw8v-3m7h-4jwg

Опубликовано: 08 фев. 2022
Источник: github
Github: Не прошло ревью

Описание

BeyondTrust Secure Remote Access Base Software through 6.0.1 allows an attacker to achieve full admin access to the appliance, by tricking the administrator into creating a new admin account through an XSS/CSRF attack involving a crafted request to the /appliance/users?action=edit endpoint. This cross-site-scripting (XSS) vulnerability occurs when it does not properly sanitize an unauthenticated crafted web request to the server

BeyondTrust Secure Remote Access Base Software through 6.0.1 allows an attacker to achieve full admin access to the appliance, by tricking the administrator into creating a new admin account through an XSS/CSRF attack involving a crafted request to the /appliance/users?action=edit endpoint. This cross-site-scripting (XSS) vulnerability occurs when it does not properly sanitize an unauthenticated crafted web request to the server

EPSS

Процентиль: 96%
0.27167
Средний

Дефекты

CWE-352
CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
около 4 лет назад

A cross-site scripting (XSS) vulnerability has been reported and confirmed for BeyondTrust Secure Remote Access Base Software version 6.0.1 and older, which allows the injection of unauthenticated, specially-crafted web requests without proper sanitization.

EPSS

Процентиль: 96%
0.27167
Средний

Дефекты

CWE-352
CWE-79