Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q7h8-385m-x32m

Опубликовано: 22 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.6

Описание

SAP Learning Solution is vulnerable to Cross-Site Request Forgery (CSRF), allowing an attacker to trick authenticated user into sending unintended requests to the server. GET-based OData function is named in a way that it violates the expected behaviour. This issue could impact both the confidentiality and integrity of the application without affecting the availability.

SAP Learning Solution is vulnerable to Cross-Site Request Forgery (CSRF), allowing an attacker to trick authenticated user into sending unintended requests to the server. GET-based OData function is named in a way that it violates the expected behaviour. This issue could impact both the confidentiality and integrity of the application without affecting the availability.

EPSS

Процентиль: 5%
0.00023
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 4.6
nvd
10 месяцев назад

SAP Learning Solution is vulnerable to Cross-Site Request Forgery (CSRF), allowing an attacker to trick authenticated user into sending unintended requests to the server. GET-based OData function is named in a way that it violates the expected behaviour. This issue could impact both the confidentiality and integrity of the application without affecting the availability.

CVSS3: 4.6
fstec
10 месяцев назад

Уязвимость функции OData программной платформы SAP S/4HANA, позволяющая нарушителю оказывать влияние на целостность и конфиденциальность защищаемой информации

EPSS

Процентиль: 5%
0.00023
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-352