Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wx76-4vvv-7j37

Опубликовано: 29 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.1
CVSS3: 5.3

Описание

Liman 0.7 contains a cross-site request forgery vulnerability that allows attackers to manipulate user account settings without proper request validation. Attackers can craft malicious HTML forms to change user passwords or modify account information by tricking logged-in users into submitting unauthorized requests.

Liman 0.7 contains a cross-site request forgery vulnerability that allows attackers to manipulate user account settings without proper request validation. Attackers can craft malicious HTML forms to change user passwords or modify account information by tricking logged-in users into submitting unauthorized requests.

EPSS

Процентиль: 10%
0.00036
Низкий

5.1 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-565

Связанные уязвимости

CVSS3: 5.3
nvd
10 дней назад

Liman 0.7 contains a cross-site request forgery vulnerability that allows attackers to manipulate user account settings without proper request validation. Attackers can craft malicious HTML forms to change user passwords or modify account information by tricking logged-in users into submitting unauthorized requests.

EPSS

Процентиль: 10%
0.00036
Низкий

5.1 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-565