Описание
Cross-site request forgery (CSRF) vulnerability in the Your_account module in CMSphp 0.21 allows remote attackers to hijack the authentication of administrators for requests that change an administrator password via the pseudo, pwd, and uid parameters in an admin_info_user_verif action.
Ссылки
- Broken LinkExploit
- Broken LinkVendor Advisory
- Broken LinkExploit
- Broken LinkVendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:cmsphp_project:cmsphp:0.21:*:*:*:*:*:*:*
EPSS
Процентиль: 38%
0.00168
Низкий
8.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-352
Связанные уязвимости
CVSS3: 8.8
github
почти 4 года назад
Cross-site request forgery (CSRF) vulnerability in the Your_account module in CMSphp 0.21 allows remote attackers to hijack the authentication of administrators for requests that change an administrator password via the pseudo, pwd, and uid parameters in an admin_info_user_verif action.
EPSS
Процентиль: 38%
0.00168
Низкий
8.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-352