Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gw6h-pq4q-jjr4

Опубликовано: 08 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Multiple Cross-Site Request Forgery (CSRF) chaining in NCR Terminal Handler v.1.5.1 allows privileges to be escalated by an attacker through a crafted request involving user account creation and adding the user to an administrator group. This is exploited by an undisclosed function in the WSDL that lacks security controls and can accept custom content types.

Multiple Cross-Site Request Forgery (CSRF) chaining in NCR Terminal Handler v.1.5.1 allows privileges to be escalated by an attacker through a crafted request involving user account creation and adding the user to an administrator group. This is exploited by an undisclosed function in the WSDL that lacks security controls and can accept custom content types.

EPSS

Процентиль: 24%
0.00081
Низкий

8.8 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
nvd
около 2 лет назад

Multiple Cross-Site Request Forgery (CSRF) chaining in NCR Terminal Handler v.1.5.1 allows privileges to be escalated by an attacker through a crafted request involving user account creation and adding the user to an administrator group. This is exploited by an undisclosed function in the WSDL that lacks security controls and can accept custom content types.

EPSS

Процентиль: 24%
0.00081
Низкий

8.8 High

CVSS3

Дефекты

CWE-352