Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r234-gvxh-m2fv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

A Cross-Origin Resource Sharing (CORS) vulnerability found in UniFi Protect application Version 1.19.2 and earlier allows a malicious actor who has convinced a privileged user to access a URL with malicious code to take over said user’s account.This vulnerability is fixed in UniFi Protect application Version 1.20.0 and later.

A Cross-Origin Resource Sharing (CORS) vulnerability found in UniFi Protect application Version 1.19.2 and earlier allows a malicious actor who has convinced a privileged user to access a URL with malicious code to take over said user’s account.This vulnerability is fixed in UniFi Protect application Version 1.20.0 and later.

EPSS

Процентиль: 63%
0.00439
Низкий

8.8 High

CVSS3

Дефекты

CWE-668

Связанные уязвимости

CVSS3: 8.8
nvd
около 4 лет назад

A Cross-Origin Resource Sharing (CORS) vulnerability found in UniFi Protect application Version 1.19.2 and earlier allows a malicious actor who has convinced a privileged user to access a URL with malicious code to take over said user’s account.This vulnerability is fixed in UniFi Protect application Version 1.20.0 and later.

EPSS

Процентиль: 63%
0.00439
Низкий

8.8 High

CVSS3

Дефекты

CWE-668