Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v9pp-qqfq-3qvw

Опубликовано: 07 мая 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

Cross-Site Request Forgery vulnerability in Socomec Net Vision, version 7.20. This vulnerability could allow an attacker to trick registered users into performing critical actions, such as adding and updating accounts, due to lack of proper sanitisation of the ‘set_param.cgi’ file.

Cross-Site Request Forgery vulnerability in Socomec Net Vision, version 7.20. This vulnerability could allow an attacker to trick registered users into performing critical actions, such as adding and updating accounts, due to lack of proper sanitisation of the ‘set_param.cgi’ file.

EPSS

Процентиль: 18%
0.00056
Низкий

7.1 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 7.1
nvd
почти 2 года назад

Cross-Site Request Forgery vulnerability in Socomec Net Vision, version 7.20. This vulnerability could allow an attacker to trick registered users into performing critical actions, such as adding and updating accounts, due to lack of proper sanitisation of the ‘set_param.cgi’ file.

EPSS

Процентиль: 18%
0.00056
Низкий

7.1 High

CVSS3

Дефекты

CWE-352