Количество 2
Количество 2
CVE-2024-36076
Cross-Site WebSocket Hijacking in SysReptor from version 2024.28 to version 2024.30 causes attackers to escalate privileges and obtain sensitive information when a logged-in SysReptor user visits a malicious same-site subdomain in the same browser session.
GHSA-rw3m-9ff4-qmp2
Syslifters SysReptor before 2024.40 has a CSRF vulnerability for WebSocket connections.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-36076 Cross-Site WebSocket Hijacking in SysReptor from version 2024.28 to version 2024.30 causes attackers to escalate privileges and obtain sensitive information when a logged-in SysReptor user visits a malicious same-site subdomain in the same browser session. | CVSS3: 8.8 | 0% Низкий | больше 1 года назад | |
GHSA-rw3m-9ff4-qmp2 Syslifters SysReptor before 2024.40 has a CSRF vulnerability for WebSocket connections. | CVSS3: 8.8 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу