Описание
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allows an attacker to perform unauthorized actions such as user deletion, password resets, and privilege escalation due to missing CSRF protections.
Ссылки
- Exploit
- Product
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:frappe:erpnext:14.74.3:*:*:*:*:*:*:*
cpe:2.3:a:frappe:erpnext:14.82.1:*:*:*:*:*:*:*
EPSS
Процентиль: 38%
0.00169
Низкий
8.1 High
CVSS3
Дефекты
CWE-352
Связанные уязвимости
CVSS3: 8.1
github
9 месяцев назад
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allows an attacker to perform unauthorized actions such as user deletion, password resets, and privilege escalation due to missing CSRF protections.
EPSS
Процентиль: 38%
0.00169
Низкий
8.1 High
CVSS3
Дефекты
CWE-352