Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vj65-f4hc-r425

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover).

GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover).

EPSS

Процентиль: 78%
0.01214
Низкий

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8
ubuntu
почти 4 года назад

GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover).

CVSS3: 8
redhat
почти 4 года назад

GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover).

CVSS3: 8
nvd
почти 4 года назад

GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover).

CVSS3: 8
debian
почти 4 года назад

GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csr ...

suse-cvrf
почти 4 года назад

Security update for mailman

EPSS

Процентиль: 78%
0.01214
Низкий

Дефекты

CWE-352