Описание
Avenwu Whistle Cross-Site Request Forgery (CSRF)
Cross-Site Request Forgery (CSRF) in Avenwu Whistle v.2.9.90 and before allows attackers to perform malicious API calls, resulting in the execution of arbitrary code on the victim's machine.
Пакеты
Наименование
whistle
npm
Затронутые версииВерсия исправления
<= 2.9.90
Отсутствует
Связанные уязвимости
CVSS3: 8.8
nvd
около 1 года назад
Cross-Site Request Forgery (CSRF) in Avenwu Whistle v.2.9.90 and before allows attackers to perform malicious API calls, resulting in the execution of arbitrary code on the victim's machine.