Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g27c-w2v7-88xp

Опубликовано: 13 дек. 2023
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Cross Site Request Forgery in Silverpeas

The "userModify" feature of Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) leading to privilege escalation. If an administrator goes to a malicious URL while being authenticated to the Silverpeas application, the CSRF with execute making the attacker an administrator user in the application.

Пакеты

Наименование

org.silverpeas.core:silverpeas-core-web

maven
Затронутые версииВерсия исправления

< 6.3.2

6.3.2

EPSS

Процентиль: 35%
0.00144
Низкий

8.8 High

CVSS3

Дефекты

CWE-352
CWE-79

Связанные уязвимости

CVSS3: 8.8
nvd
около 2 лет назад

The "userModify" feature of Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) leading to privilege escalation. If an administrator goes to a malicious URL while being authenticated to the Silverpeas application, the CSRF with execute making the attacker an administrator user in the application.

EPSS

Процентиль: 35%
0.00144
Низкий

8.8 High

CVSS3

Дефекты

CWE-352
CWE-79