Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vf7h-6246-hm43

Опубликовано: 19 нояб. 2021
Источник: github
Github: Прошло ревью
CVSS3: 4.2

Описание

The disqualify lead action may be executed without CSRF token check

Summary

The attacker is able to disqualify any Lead with a Cross-Site Request Forgery (CSRF) attack.

Workarounds

There are no workarounds that address this vulnerability.

Пакеты

Наименование

oro/crm

composer
Затронутые версииВерсия исправления

>= 3.1.0, < 4.1.17

4.1.17

Наименование

oro/crm

composer
Затронутые версииВерсия исправления

>= 4.2.0, < 4.2.7

4.2.7

EPSS

Процентиль: 29%
0.00106
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 4.2
nvd
около 4 лет назад

OroCRM is an open source Client Relationship Management (CRM) application. Affected versions we found to suffer from a vulnerability which could an attacker is able to disqualify any Lead with a Cross-Site Request Forgery (CSRF) attack. There are no workarounds that address this vulnerability and all users are advised to update their package.

EPSS

Процентиль: 29%
0.00106
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-352