Описание
A successful CSRF attack could force the user to perform state changing requests on the application. If the victim is an administrative account, a CSRF attack could compromise the entire web application.
Ссылки
- Third Party AdvisoryUS Government Resource
- Third Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1
Одновременно
cpe:2.3:o:efacec:bcu_500_firmware:4.07:*:*:*:*:*:*:*
cpe:2.3:h:efacec:bcu_500:-:*:*:*:*:*:*:*
EPSS
Процентиль: 17%
0.00056
Низкий
8.2 High
CVSS3
8.8 High
CVSS3
Дефекты
CWE-352
CWE-352
Связанные уязвимости
CVSS3: 8.2
github
около 2 лет назад
A successful CSRF attack could force the user to perform state changing requests on the application. If the victim is an administrative account, a CSRF attack could compromise the entire web application.
EPSS
Процентиль: 17%
0.00056
Низкий
8.2 High
CVSS3
8.8 High
CVSS3
Дефекты
CWE-352
CWE-352