Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-22194

Опубликовано: 09 янв. 2026
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

GestSup versions up to and including 3.2.60 contain a cross-site request forgery (CSRF) vulnerability where the application does not verify the authenticity of client requests. An attacker can induce a logged-in user to submit crafted requests that perform actions with the victim's privileges. This can be exploited to create privileged accounts by targeting the administrative user creation endpoint.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gestsup:gestsup:*:*:*:*:*:*:*:*
Версия до 3.2.56 (включая)

EPSS

Процентиль: 5%
0.00023
Низкий

8.8 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
github
30 дней назад

GestSup versions up to and including 3.2.56 contain a cross-site request forgery (CSRF) vulnerability where the application does not verify the authenticity of client requests. An attacker can induce a logged-in user to submit crafted requests that perform actions with the victim's privileges. This can be exploited to create privileged accounts by targeting the administrative user creation endpoint.

EPSS

Процентиль: 5%
0.00023
Низкий

8.8 High

CVSS3

Дефекты

CWE-352