Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gf5x-68xp-22rx

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Cross-site request forgery (CSRF) vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote attackers to hijack the authentication of admins for requests that install packages via the package parameter in an install2 action.

Cross-site request forgery (CSRF) vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote attackers to hijack the authentication of admins for requests that install packages via the package parameter in an install2 action.

EPSS

Процентиль: 83%
0.01932
Низкий

Дефекты

CWE-352

Связанные уязвимости

nvd
почти 17 лет назад

Cross-site request forgery (CSRF) vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote attackers to hijack the authentication of admins for requests that install packages via the package parameter in an install2 action.

EPSS

Процентиль: 83%
0.01932
Низкий

Дефекты

CWE-352