Описание
An issue was discovered in SmartStoreNET before 4.1.0. Lack of Cross Site Request Forgery (CSRF) protection may lead to elevation of privileges (e.g., /admin/customer/create to create an admin account).
Ссылки
- Release NotesThird Party Advisory
- ExploitThird Party Advisory
- Release NotesThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.1.0 (исключая)
cpe:2.3:a:smartstore:smartstorenet:*:*:*:*:*:*:*:*
EPSS
Процентиль: 40%
0.00186
Низкий
8.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-352
EPSS
Процентиль: 40%
0.00186
Низкий
8.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-352