Описание
A Cross-Site Request Forgery (CSRF) vulnerability in changeUsername.php in SourceCodester Stock Management System v1.0 allows remote attackers to deny future logins by changing an authenticated victim's username when they visit a third-party site.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- ProductThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ProductThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:stock_management_system_project:stock_management_system:1.0:*:*:*:*:*:*:*
EPSS
Процентиль: 44%
0.00218
Низкий
7.1 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-352
Связанные уязвимости
github
больше 3 лет назад
A Cross-Site Request Forgery (CSRF) vulnerability in changeUsername.php in SourceCodester Stock Management System v1.0 allows remote attackers to deny future logins by changing an authenticated victim's username when they visit a third-party site.
EPSS
Процентиль: 44%
0.00218
Низкий
7.1 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-352