Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rv28-58vf-v4pv

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

An issue was discovered in CMS Made Simple 2.2.8. In the administrator page admin/changegroupperm.php, it is possible to send a crafted value in the sel_groups parameter that leads to authenticated object injection.

An issue was discovered in CMS Made Simple 2.2.8. In the administrator page admin/changegroupperm.php, it is possible to send a crafted value in the sel_groups parameter that leads to authenticated object injection.

EPSS

Процентиль: 77%
0.01005
Низкий

7.2 High

CVSS3

Дефекты

CWE-1321
CWE-915

Связанные уязвимости

CVSS3: 7.2
nvd
почти 7 лет назад

An issue was discovered in CMS Made Simple 2.2.8. In the administrator page admin/changegroupperm.php, it is possible to send a crafted value in the sel_groups parameter that leads to authenticated object injection.

EPSS

Процентиль: 77%
0.01005
Низкий

7.2 High

CVSS3

Дефекты

CWE-1321
CWE-915