Описание
There is a security vulnerability in login form related to Cross-site Request Forgery which prevents user to login after attacker spam to login and system blocked victim's account.
Ссылки
- MitigationVendor Advisory
- MitigationVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 9.0 (включая) до 10.0.7.0 (исключая)
cpe:2.3:a:hcltech:bigfix_inventory:*:*:*:*:*:*:*:*
EPSS
Процентиль: 24%
0.00084
Низкий
4.3 Medium
CVSS3
6.5 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-352
CWE-352
Связанные уязвимости
CVSS3: 6.5
github
почти 4 года назад
There is a security vulnerability in login form related to Cross-site Request Forgery which prevents user to login after attacker spam to login and system blocked victim's account.
EPSS
Процентиль: 24%
0.00084
Низкий
4.3 Medium
CVSS3
6.5 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-352
CWE-352