Логотип exploitDog
bind:CVE-2020-11818
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-11818

Количество 2

Количество 2

nvd логотип

CVE-2020-11818

почти 6 лет назад

In Rukovoditel 2.5.2 has a form_session_token value to prevent CSRF attacks. This protection mechanism can be bypassed with another user's valid token. Thus, an attacker can change the Admin password by using a CSRF attack and escalate his/her privileges.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-hfxg-vggv-f594

больше 3 лет назад

In Rukovoditel 2.5.2 has a form_session_token value to prevent CSRF attacks. This protection mechanism can be bypassed with another user's valid token. Thus, an attacker can change the Admin password by using a CSRF attack and escalate his/her privileges.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-11818

In Rukovoditel 2.5.2 has a form_session_token value to prevent CSRF attacks. This protection mechanism can be bypassed with another user's valid token. Thus, an attacker can change the Admin password by using a CSRF attack and escalate his/her privileges.

CVSS3: 8.8
0%
Низкий
почти 6 лет назад
github логотип
GHSA-hfxg-vggv-f594

In Rukovoditel 2.5.2 has a form_session_token value to prevent CSRF attacks. This protection mechanism can be bypassed with another user's valid token. Thus, an attacker can change the Admin password by using a CSRF attack and escalate his/her privileges.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу