Описание
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST request with injected HTML data that is later leveraged to send emails from a customer trusted email address.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 9.1 (исключая)
cpe:2.3:a:cipplanner:cipace:*:*:*:*:*:*:*:*
EPSS
Процентиль: 78%
0.01114
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-74
Связанные уязвимости
github
больше 3 лет назад
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST request with injected HTML data that is later leveraged to send emails from a customer trusted email address.
EPSS
Процентиль: 78%
0.01114
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-74