Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-39286

Опубликовано: 14 сент. 2023
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2304.102 could allow an unauthenticated attacker to perform a Cross Site Request Forgery (CSRF) attack due to insufficient request validation. A successful exploit could allow an attacker to provide a modified URL, potentially enabling them to modify system configuration settings.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mitel:connect_mobility_router:*:*:*:*:*:*:*:*
Версия до 9.6.2307.111 (исключая)

EPSS

Процентиль: 30%
0.0011
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 4.3
github
больше 2 лет назад

A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2304.102 could allow an unauthenticated attacker to perform a Cross Site Request Forgery (CSRF) attack due to insufficient request validation. A successful exploit could allow an attacker to provide a modified URL, potentially enabling them to modify system configuration settings.

EPSS

Процентиль: 30%
0.0011
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-352