Описание
Cross-site request forgery (CSRF) vulnerability in users_maint.html in KrisonAV CMS before 3.0.2 allows remote attackers to hijack the authentication of administrators for requests that create user accounts via a crafted request.
Ссылки
- Exploit
- Vendor Advisory
- Exploit
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.0.1 (включая)
Одно из
cpe:2.3:a:krisonav:krisonav:*:*:*:*:*:*:*:*
cpe:2.3:a:krisonav:krisonav:0.9.3:*:*:*:*:*:*:*
cpe:2.3:a:krisonav:krisonav:0.9.4:*:*:*:*:*:*:*
cpe:2.3:a:krisonav:krisonav:0.9.5:*:*:*:*:*:*:*
cpe:2.3:a:krisonav:krisonav:0.9.6:*:*:*:*:*:*:*
cpe:2.3:a:krisonav:krisonav:0.9.7:*:*:*:*:*:*:*
cpe:2.3:a:krisonav:krisonav:1.0.0:beta:*:*:*:*:*:*
cpe:2.3:a:krisonav:krisonav:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:krisonav:krisonav:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:krisonav:krisonav:1.1.35:*:*:*:*:*:*:*
cpe:2.3:a:krisonav:krisonav:2.0.1:beta:*:*:*:*:*:*
cpe:2.3:a:krisonav:krisonav:2.1.3:*:*:*:*:*:*:*
cpe:2.3:a:krisonav:krisonav:2.1.5:*:*:*:*:*:*:*
cpe:2.3:a:krisonav:krisonav:2.1.6:*:*:*:*:*:*:*
cpe:2.3:a:krisonav:krisonav:3.0.0:*:*:*:*:*:*:*
EPSS
Процентиль: 70%
0.00656
Низкий
6.8 Medium
CVSS2
Дефекты
CWE-352
Связанные уязвимости
github
больше 3 лет назад
Cross-site request forgery (CSRF) vulnerability in users_maint.html in KrisonAV CMS before 3.0.2 allows remote attackers to hijack the authentication of administrators for requests that create user accounts via a crafted request.
EPSS
Процентиль: 70%
0.00656
Низкий
6.8 Medium
CVSS2
Дефекты
CWE-352