Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v8f8-f9x3-fqw4

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In Zmanda Management Console 3.3.9, ZMC_Admin_Advanced?form=adminTasks&action=Apply&command= allows CSRF, as demonstrated by command injection with shell metacharacters. This may depend on weak default credentials.

In Zmanda Management Console 3.3.9, ZMC_Admin_Advanced?form=adminTasks&action=Apply&command= allows CSRF, as demonstrated by command injection with shell metacharacters. This may depend on weak default credentials.

EPSS

Процентиль: 48%
0.0025
Низкий

Связанные уязвимости

CVSS3: 8.8
nvd
около 6 лет назад

In Zmanda Management Console 3.3.9, ZMC_Admin_Advanced?form=adminTasks&action=Apply&command= allows CSRF, as demonstrated by command injection with shell metacharacters. This may depend on weak default credentials.

EPSS

Процентиль: 48%
0.0025
Низкий