Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-10232

Опубликовано: 11 июл. 2018
Источник: nvd
CVSS3: 6.5
CVSS2: 4.3
EPSS Низкий

Описание

Cross-site request forgery (CSRF) vulnerability in TOPdesk before 8.05.017 (June 2018 version) and before 5.7.SR9 allows remote attackers to hijack the authentication of authenticated users for requests that can obtain sensitive information via unspecified vectors.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:topdesk:topdesk:*:*:*:*:*:*:*:*
Версия от 8.05.001 (включая) до 8.05.017 (исключая)
cpe:2.3:a:topdesk:topdesk:5.7:-:*:*:*:*:*:*
cpe:2.3:a:topdesk:topdesk:5.7:service_release1:*:*:*:*:*:*
cpe:2.3:a:topdesk:topdesk:5.7:service_release2:*:*:*:*:*:*
cpe:2.3:a:topdesk:topdesk:5.7:service_release3:*:*:*:*:*:*
cpe:2.3:a:topdesk:topdesk:5.7:service_release4:*:*:*:*:*:*
cpe:2.3:a:topdesk:topdesk:5.7:service_release5:*:*:*:*:*:*
cpe:2.3:a:topdesk:topdesk:5.7:service_release6:*:*:*:*:*:*
cpe:2.3:a:topdesk:topdesk:5.7:service_release7:*:*:*:*:*:*
cpe:2.3:a:topdesk:topdesk:5.7:service_release8:*:*:*:*:*:*

EPSS

Процентиль: 26%
0.00091
Низкий

6.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 6.5
github
больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in TOPdesk before 8.05.017 (June 2018 version) and before 5.7.SR9 allows remote attackers to hijack the authentication of authenticated users for requests that can obtain sensitive information via unspecified vectors.

EPSS

Процентиль: 26%
0.00091
Низкий

6.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-352