Логотип exploitDog
bind:CVE-2020-21989
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-21989

Количество 2

Количество 2

nvd логотип

CVE-2020-21989

почти 5 лет назад

HomeAutomation 3.3.2 is affected by Cross Site Request Forgery (CSRF). The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-q6p3-r2m4-6q5r

больше 3 лет назад

HomeAutomation 3.3.2 is affected by Cross Site Request Forgery (CSRF). The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-21989

HomeAutomation 3.3.2 is affected by Cross Site Request Forgery (CSRF). The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.

CVSS3: 8.8
0%
Низкий
почти 5 лет назад
github логотип
GHSA-q6p3-r2m4-6q5r

HomeAutomation 3.3.2 is affected by Cross Site Request Forgery (CSRF). The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу