Описание
AdRem NetCrunch 10.6.0.4587 has a Cross-Site Request Forgery (CSRF) vulnerability in the NetCrunch web client. Successful exploitation requires a logged-in user to open a malicious page and leads to account takeover.
Ссылки
- ExploitThird Party Advisory
- Product
- ExploitThird Party Advisory
- Product
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:adremsoft:netcrunch:10.6.0.4587:*:*:*:*:*:*:*
EPSS
Процентиль: 31%
0.00115
Низкий
5.4 Medium
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-352
Связанные уязвимости
github
больше 3 лет назад
AdRem NetCrunch 10.6.0.4587 has a Cross-Site Request Forgery (CSRF) vulnerability in the NetCrunch web client. Successful exploitation requires a logged-in user to open a malicious page and leads to account takeover.
EPSS
Процентиль: 31%
0.00115
Низкий
5.4 Medium
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-352