Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x84r-583w-g39w

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the “Web Help Desk Getting Started Wizard”, especially the admin account creationpage, from a non-privileged IP address network range or loopback address by intercepting the HTTP request and changing the referrer from the public IP address to the loopback.

Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the “Web Help Desk Getting Started Wizard”, especially the admin account creationpage, from a non-privileged IP address network range or loopback address by intercepting the HTTP request and changing the referrer from the public IP address to the loopback.

EPSS

Процентиль: 65%
0.00485
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-290
CWE-863

Связанные уязвимости

CVSS3: 5.3
nvd
больше 4 лет назад

Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the 'Web Help Desk Getting Started Wizard', especially the admin account creation page, from a non-privileged IP address network range or loopback address by intercepting the HTTP request and changing the referrer from the public IP address to the loopback.

EPSS

Процентиль: 65%
0.00485
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-290
CWE-863