Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vfgg-4hvr-6rq9

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Magento prior to 1.9.4.3 and prior to 1.14.4.3 included a user's CSRF token in the URL of a GET request. This could be exploited by an attacker with access to network traffic to perform unauthorized actions.

Magento prior to 1.9.4.3 and prior to 1.14.4.3 included a user's CSRF token in the URL of a GET request. This could be exploited by an attacker with access to network traffic to perform unauthorized actions.

EPSS

Процентиль: 20%
0.00065
Низкий

Связанные уязвимости

CVSS3: 7.5
nvd
больше 6 лет назад

Magento prior to 1.9.4.3 and prior to 1.14.4.3 included a user's CSRF token in the URL of a GET request. This could be exploited by an attacker with access to network traffic to perform unauthorized actions.

EPSS

Процентиль: 20%
0.00065
Низкий