Количество 2
Количество 2
CVE-2021-23404
This affects all versions of package sqlite-web. The SQL dashboard area allows sensitive actions to be performed without validating that the request originated from the application. This could enable an attacker to trick a user into performing these actions unknowingly through a Cross Site Request Forgery (CSRF) attack.
GHSA-2j58-pwwv-x666
Cross-Site Request Forgery in sqlite-web
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-23404 This affects all versions of package sqlite-web. The SQL dashboard area allows sensitive actions to be performed without validating that the request originated from the application. This could enable an attacker to trick a user into performing these actions unknowingly through a Cross Site Request Forgery (CSRF) attack. | CVSS3: 7.6 | 0% Низкий | больше 4 лет назад | |
GHSA-2j58-pwwv-x666 Cross-Site Request Forgery in sqlite-web | CVSS3: 7.6 | 0% Низкий | больше 4 лет назад |
Уязвимостей на страницу