Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hjpj-63j9-h7v4

Опубликовано: 27 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service does not implement CSRF protections. An attacker who social engineers a valid user into clicking a malicious link or visiting a malicious website may be able to submit requests to the Job Status Service without the user's knowledge.

An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service does not implement CSRF protections. An attacker who social engineers a valid user into clicking a malicious link or visiting a malicious website may be able to submit requests to the Job Status Service without the user's knowledge.

EPSS

Процентиль: 5%
0.00022
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 6.1
nvd
3 месяца назад

An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service does not implement CSRF protections. An attacker who social engineers a valid user into clicking a malicious link or visiting a malicious website may be able to submit requests to the Job Status Service without the user's knowledge.

EPSS

Процентиль: 5%
0.00022
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-352