Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vj65-f4hc-r425

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover).

GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover).

EPSS

Процентиль: 78%
0.01214
Низкий

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8
ubuntu
больше 3 лет назад

GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover).

CVSS3: 8
redhat
больше 3 лет назад

GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover).

CVSS3: 8
nvd
больше 3 лет назад

GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover).

CVSS3: 8
debian
больше 3 лет назад

GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csr ...

suse-cvrf
больше 3 лет назад

Security update for mailman

EPSS

Процентиль: 78%
0.01214
Низкий

Дефекты

CWE-352