Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rwhp-9vfh-g7v8

Опубликовано: 09 мая 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.9

Описание

Cross-Site Request Forgery (CSRF) vulnerability in Sparx Systems Pro Cloud Server allows Cross-Site Request Forgery to perform Session Hijacking. Cross-Site Request Forgery is present at the whole application but it can be used to change the Pro Cloud Server Configuration password. This issue affects Pro Cloud Server: earlier than 6.0.165.

Cross-Site Request Forgery (CSRF) vulnerability in Sparx Systems Pro Cloud Server allows Cross-Site Request Forgery to perform Session Hijacking. Cross-Site Request Forgery is present at the whole application but it can be used to change the Pro Cloud Server Configuration password. This issue affects Pro Cloud Server: earlier than 6.0.165.

EPSS

Процентиль: 19%
0.00062
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-352

Связанные уязвимости

nvd
9 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in Sparx Systems Pro Cloud Server allows Cross-Site Request Forgery to perform Session Hijacking. Cross-Site Request Forgery is present at the whole application but it can be used to change the Pro Cloud Server Configuration password. This issue affects Pro Cloud Server: earlier than 6.0.165.

EPSS

Процентиль: 19%
0.00062
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-352