Описание
Cross-Site Request Forgery (CSRF) vulnerability in FuseTalk 2.0 allows remote attackers to create arbitrary accounts via a link to adduser.cfm.
Ссылки
- Mailing List
- Broken LinkVendor Advisory
- Broken LinkThird Party AdvisoryVDB Entry
- Broken Link
- Broken LinkExploitThird Party AdvisoryVDB EntryVendor Advisory
- Third Party AdvisoryVDB Entry
- Mailing List
- Broken LinkVendor Advisory
- Broken LinkThird Party AdvisoryVDB Entry
- Broken Link
- Broken LinkExploitThird Party AdvisoryVDB EntryVendor Advisory
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:fusetalk:fusetalk:2.0:-:*:*:*:*:*:*
EPSS
Процентиль: 90%
0.05112
Низкий
6.5 Medium
CVSS3
7.5 High
CVSS2
Дефекты
CWE-352
Связанные уязвимости
CVSS3: 6.5
github
почти 4 года назад
Cross-Site Request Forgery (CSRF) vulnerability in FuseTalk 2.0 allows remote attackers to create arbitrary accounts via a link to adduser.cfm.
EPSS
Процентиль: 90%
0.05112
Низкий
6.5 Medium
CVSS3
7.5 High
CVSS2
Дефекты
CWE-352