Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-51381

Опубликовано: 05 нояб. 2024
Источник: nvd
CVSS3: 8.4
EPSS Низкий

Описание

Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 that allows attackers to perform actions reserved for administrators, including creating admin accounts. This critical flaw can lead to unauthorized activities, compromising the security and integrity of the platform, especially if an attacker gains administrative control.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:jatos:jatos:3.9.3:*:*:*:*:*:*:*

EPSS

Процентиль: 22%
0.00074
Низкий

8.4 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.4
github
больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 that allows attackers to perform actions reserved for administrators, including creating admin accounts. This critical flaw can lead to unauthorized activities, compromising the security and integrity of the platform, especially if an attacker gains administrative control.

EPSS

Процентиль: 22%
0.00074
Низкий

8.4 High

CVSS3

Дефекты

CWE-352