Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-grhv-p8rf-rc43

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.7

Описание

Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authentication of privileged users for requests that shutdown a server via a shutdown action to server-admin/proxy_ajaxprocessor.jsp.

Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authentication of privileged users for requests that shutdown a server via a shutdown action to server-admin/proxy_ajaxprocessor.jsp.

EPSS

Процентиль: 86%
0.02743
Низкий

5.7 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 5.7
nvd
почти 9 лет назад

Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authentication of privileged users for requests that shutdown a server via a shutdown action to server-admin/proxy_ajaxprocessor.jsp.

EPSS

Процентиль: 86%
0.02743
Низкий

5.7 Medium

CVSS3

Дефекты

CWE-352