Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vhxp-r6hh-hf7v

Опубликовано: 03 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8

Описание

Rainworx Auctionworx < 3.1R2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack that allows an authenticated user to upgrade his account to admin and gain access to the auctionworx admin control panel. This vulnerability affects AuctionWorx Enterprise and AuctionWorx: Events Edition.

Rainworx Auctionworx < 3.1R2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack that allows an authenticated user to upgrade his account to admin and gain access to the auctionworx admin control panel. This vulnerability affects AuctionWorx Enterprise and AuctionWorx: Events Edition.

EPSS

Процентиль: 40%
0.00184
Низкий

8 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8
nvd
почти 4 года назад

Rainworx Auctionworx < 3.1R2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack that allows an authenticated user to upgrade his account to admin and gain access to the auctionworx admin control panel. This vulnerability affects AuctionWorx Enterprise and AuctionWorx: Events Edition.

EPSS

Процентиль: 40%
0.00184
Низкий

8 High

CVSS3

Дефекты

CWE-352