Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h6qg-v9qr-7prq

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

A CSRF issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. To exploit the vulnerability, an attacker can send cross-domain requests directly to the REST API for users with a valid session cookie.

A CSRF issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. To exploit the vulnerability, an attacker can send cross-domain requests directly to the REST API for users with a valid session cookie.

EPSS

Процентиль: 36%
0.00151
Низкий

8.8 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
nvd
почти 9 лет назад

A CSRF issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. To exploit the vulnerability, an attacker can send cross-domain requests directly to the REST API for users with a valid session cookie.

CVSS3: 8.8
debian
почти 9 лет назад

A CSRF issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3 ...

EPSS

Процентиль: 36%
0.00151
Низкий

8.8 High

CVSS3

Дефекты

CWE-352