Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ppq7-88c7-q879

Опубликовано: 17 нояб. 2021
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Cross-Site Request Forgery in PiranhaCMS

In PiranhaCMS, versions 4.0.0-alpha1 to 9.2.0 are vulnerable to cross-site request forgery (CSRF) when performing various actions supported by the management system, such as deleting a user, deleting a role, editing a post, deleting a media folder etc., when an ID is known.

Пакеты

Наименование

Piranha

nuget
Затронутые версииВерсия исправления

>= 4.0.0-alpha1, <= 9.2.0

10.0-alpha1

EPSS

Процентиль: 28%
0.00101
Низкий

8.1 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.1
nvd
около 4 лет назад

In PiranhaCMS, versions 4.0.0-alpha1 to 9.2.0 are vulnerable to cross-site request forgery (CSRF) when performing various actions supported by the management system, such as deleting a user, deleting a role, editing a post, deleting a media folder etc., when an ID is known.

EPSS

Процентиль: 28%
0.00101
Низкий

8.1 High

CVSS3

Дефекты

CWE-352