Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pgjv-446p-p2p9

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A cross-site request forgery (CSRF) vulnerability exists in Streama up to and including v1.10.3. The application does not have CSRF checks in place when performing actions such as uploading local files. As a result, attackers could make a logged-in administrator upload arbitrary local files via a CSRF attack and send them to the attacker.

A cross-site request forgery (CSRF) vulnerability exists in Streama up to and including v1.10.3. The application does not have CSRF checks in place when performing actions such as uploading local files. As a result, attackers could make a logged-in administrator upload arbitrary local files via a CSRF attack and send them to the attacker.

EPSS

Процентиль: 39%
0.00172
Низкий

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
nvd
больше 4 лет назад

A cross-site request forgery (CSRF) vulnerability exists in Streama up to and including v1.10.3. The application does not have CSRF checks in place when performing actions such as uploading local files. As a result, attackers could make a logged-in administrator upload arbitrary local files via a CSRF attack and send them to the attacker.

EPSS

Процентиль: 39%
0.00172
Низкий

Дефекты

CWE-352