Описание
An issue was discovered in the Admin Notes plugin 1.1 for MyBB. CSRF allows an attacker to remotely delete all admin notes via an admin/index.php?empty=table (aka Clear Table) action.
Ссылки
- Release NotesThird Party Advisory
- PatchThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- Release NotesThird Party Advisory
- PatchThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:admin_notes_project:admin_notes:1.1:*:*:*:*:mybb:*:*
EPSS
Процентиль: 42%
0.00197
Низкий
6.5 Medium
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-352
Связанные уязвимости
CVSS3: 6.5
github
больше 3 лет назад
An issue was discovered in the Admin Notes plugin 1.1 for MyBB. CSRF allows an attacker to remotely delete all admin notes via an admin/index.php?empty=table (aka Clear Table) action.
EPSS
Процентиль: 42%
0.00197
Низкий
6.5 Medium
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-352