Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vm6r-4p4v-232x

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

October CMS CSRF

Cross-Site Request Forgery exists in OctoberCMS 1.0.426 (aka Build 426) due to improper validation of CSRF tokens for postback handling, allowing an attacker to successfully take over the victim's account. The attack bypasses a protection mechanism involving X-CSRF headers and CSRF tokens via a certain _handler postback variable.

Пакеты

Наименование

october/october

composer
Затронутые версииВерсия исправления

<= 1.0.426

1.0.427

EPSS

Процентиль: 60%
0.00403
Низкий

8.8 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
nvd
больше 8 лет назад

Cross-Site Request Forgery exists in OctoberCMS 1.0.426 (aka Build 426) due to improper validation of CSRF tokens for postback handling, allowing an attacker to successfully take over the victim's account. The attack bypasses a protection mechanism involving X-CSRF headers and CSRF tokens via a certain _handler postback variable.

EPSS

Процентиль: 60%
0.00403
Низкий

8.8 High

CVSS3

Дефекты

CWE-352