Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xp26-fwf6-j3gx

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitrary program from its init.py file and (2) causing the victim to download, install, and enable this plugin.

CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitrary program from its init.py file and (2) causing the victim to download, install, and enable this plugin.

EPSS

Процентиль: 79%
0.01226
Низкий

8.8 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 9 лет назад

CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitrary program from its __init__.py file and (2) causing the victim to download, install, and enable this plugin.

CVSS3: 8.8
nvd
почти 9 лет назад

CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitrary program from its __init__.py file and (2) causing the victim to download, install, and enable this plugin.

CVSS3: 8.8
debian
почти 9 лет назад

CSRF was discovered in the web UI in Deluge before 1.3.14. The exploit ...

suse-cvrf
больше 8 лет назад

Security update for deluge

EPSS

Процентиль: 79%
0.01226
Низкий

8.8 High

CVSS3

Дефекты

CWE-352