Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r3c9-9j5q-pwv4

Опубликовано: 26 янв. 2023
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

magento-lts Reset Password not protected against well-timed CSRF

Impact

Password reset form is vulnerable to CSRF between time reset password link is clicked and user submits new password.

Patches

PR forthcoming

Workarounds

None

Пакеты

Наименование

openmage/magento-lts

composer
Затронутые версииВерсия исправления

< 19.4.22

19.4.22

Наименование

openmage/magento-lts

composer
Затронутые версииВерсия исправления

>= 20.0.0, < 20.0.19

20.0.19

EPSS

Процентиль: 49%
0.00255
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 4.2
nvd
около 3 лет назад

Magneto LTS (Long Term Support) is a community developed alternative to the Magento CE official releases. Versions prior to 19.4.22 and 20.0.19 are vulnerable to Cross-Site Request Forgery. The password reset form is vulnerable to CSRF between the time the reset password link is clicked and user submits new password. This issue is patched in versions 19.4.22 and 20.0.19. There are no workarounds.

EPSS

Процентиль: 49%
0.00255
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-352