Описание
Cross-site request forgery vulnerability exists in iroha Board versions v0.10.12 and earlier. If a user accesses a specially crafted URL while being logged in to the affected product, arbitrary learning histories may be registered.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.10.13 (исключая)
cpe:2.3:a:irohasoft:iroha_board:*:*:*:*:*:*:*:*
EPSS
Процентиль: 3%
0.00016
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-352
Связанные уязвимости
CVSS3: 4.3
github
8 месяцев назад
Cross-site request forgery vulnerability exists in iroha Board versions v0.10.12 and earlier. If a user accesses a specially crafted URL while being logged in to the affected product, arbitrary learning histories may be registered.
EPSS
Процентиль: 3%
0.00016
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-352