Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jffw-pcp9-w58r

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. CSRF can sometimes occur via a crafted web site for account takeover attacks.

An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. CSRF can sometimes occur via a crafted web site for account takeover attacks.

EPSS

Процентиль: 35%
0.00142
Низкий

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
nvd
больше 5 лет назад

An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. CSRF can sometimes occur via a crafted web site for account takeover attacks.

CVSS3: 8.8
debian
больше 5 лет назад

An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5. ...

EPSS

Процентиль: 35%
0.00142
Низкий

Дефекты

CWE-352