Описание
public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges.
Ссылки
- ExploitTechnical DescriptionThird Party Advisory
- Third Party AdvisoryVDB Entry
- ExploitTechnical DescriptionThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitTechnical DescriptionThird Party Advisory
- Third Party AdvisoryVDB Entry
- ExploitTechnical DescriptionThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:ladybirdweb:faveo_helpdesk:1.9.3:*:*:*:*:*:*:*
EPSS
Процентиль: 52%
0.00291
Низкий
8 High
CVSS3
6 Medium
CVSS2
Дефекты
CWE-352
Связанные уязвимости
CVSS3: 8
github
больше 3 лет назад
public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges.
EPSS
Процентиль: 52%
0.00291
Низкий
8 High
CVSS3
6 Medium
CVSS2
Дефекты
CWE-352