Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vf35-57rw-pc4w

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A CSRF token disclosure vulnerability allows a remote attacker, with access to an authenticated Management Center (MC) user's web browser history or a network device that intercepts/logs traffic to MC, to obtain CSRF tokens and use them to perform CSRF attacks against MC.

A CSRF token disclosure vulnerability allows a remote attacker, with access to an authenticated Management Center (MC) user's web browser history or a network device that intercepts/logs traffic to MC, to obtain CSRF tokens and use them to perform CSRF attacks against MC.

EPSS

Процентиль: 45%
0.00228
Низкий

Дефекты

CWE-311

Связанные уязвимости

CVSS3: 5.9
nvd
почти 6 лет назад

A CSRF token disclosure vulnerability allows a remote attacker, with access to an authenticated Management Center (MC) user's web browser history or a network device that intercepts/logs traffic to MC, to obtain CSRF tokens and use them to perform CSRF attacks against MC.

EPSS

Процентиль: 45%
0.00228
Низкий

Дефекты

CWE-311