Логотип exploitDog
bind:CVE-2020-35675
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-35675

Количество 2

Количество 2

nvd логотип

CVE-2020-35675

больше 3 лет назад

BigProf Online Invoicing System before 3.0 offers a functionality that allows an administrator to move the records of members across groups. The applicable endpoint (admin/pageTransferOwnership.php) lacks CSRF protection, resulting in an attacker being able to escalate their privileges to Administrator and effectively taking over the application.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-ccqh-vq8x-92m4

больше 3 лет назад

BigProf Online Invoicing System before 3.0 offers a functionality that allows an administrator to move the records of members across groups. The applicable endpoint (admin/pageTransferOwnership.php) lacks CSRF protection, resulting in an attacker being able to escalate their privileges to Administrator and effectively taking over the application.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-35675

BigProf Online Invoicing System before 3.0 offers a functionality that allows an administrator to move the records of members across groups. The applicable endpoint (admin/pageTransferOwnership.php) lacks CSRF protection, resulting in an attacker being able to escalate their privileges to Administrator and effectively taking over the application.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-ccqh-vq8x-92m4

BigProf Online Invoicing System before 3.0 offers a functionality that allows an administrator to move the records of members across groups. The applicable endpoint (admin/pageTransferOwnership.php) lacks CSRF protection, resulting in an attacker being able to escalate their privileges to Administrator and effectively taking over the application.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу