Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g8rv-4ccg-wc6m

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An Anti CSRF mechanism was discovered missing in the Teradici Cloud Access Connector v31 and earlier in a specific web form, which allowed an attacker with knowledge of both a machineID and user GUID to modify data if a user clicked a malicious link.

An Anti CSRF mechanism was discovered missing in the Teradici Cloud Access Connector v31 and earlier in a specific web form, which allowed an attacker with knowledge of both a machineID and user GUID to modify data if a user clicked a malicious link.

EPSS

Процентиль: 31%
0.0012
Низкий

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 6.5
nvd
почти 5 лет назад

An Anti CSRF mechanism was discovered missing in the Teradici Cloud Access Connector v31 and earlier in a specific web form, which allowed an attacker with knowledge of both a machineID and user GUID to modify data if a user clicked a malicious link.

EPSS

Процентиль: 31%
0.0012
Низкий

Дефекты

CWE-352