Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gwqv-mxv2-3769

Опубликовано: 26 мар. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /src/dede/makehtml_homepage.php allowing a remote attacker to execute arbitrary code.

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /src/dede/makehtml_homepage.php allowing a remote attacker to execute arbitrary code.

EPSS

Процентиль: 86%
0.03025
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 9.8
nvd
почти 2 года назад

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /src/dede/makehtml_homepage.php allowing a remote attacker to execute arbitrary code.

EPSS

Процентиль: 86%
0.03025
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-352