Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pr5m-xw5h-f973

Опубликовано: 23 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.1
CVSS3: 3.5

Описание

Zucchetti Axess CLOKI Access Control 1.64 contains a cross-site request forgery vulnerability that allows attackers to manipulate access control settings without user interaction. Attackers can craft malicious web pages with hidden forms to disable or modify access control parameters by tricking authenticated users into loading the page.

Zucchetti Axess CLOKI Access Control 1.64 contains a cross-site request forgery vulnerability that allows attackers to manipulate access control settings without user interaction. Attackers can craft malicious web pages with hidden forms to disable or modify access control parameters by tricking authenticated users into loading the page.

EPSS

Процентиль: 3%
0.00017
Низкий

5.1 Medium

CVSS4

3.5 Low

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 3.5
nvd
около 2 месяцев назад

Zucchetti Axess CLOKI Access Control 1.64 contains a cross-site request forgery vulnerability that allows attackers to manipulate access control settings without user interaction. Attackers can craft malicious web pages with hidden forms to disable or modify access control parameters by tricking authenticated users into loading the page.

EPSS

Процентиль: 3%
0.00017
Низкий

5.1 Medium

CVSS4

3.5 Low

CVSS3

Дефекты

CWE-352