Логотип exploitDog
bind:CVE-2022-31000
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-31000

Количество 2

Количество 2

nvd логотип

CVE-2022-31000

больше 3 лет назад

solidus_backend is the admin interface for the Solidus e-commerce framework. Versions prior to 3.1.6, 3.0.6, and 2.11.16 contain a cross-site request forgery (CSRF) vulnerability. The vulnerability allows attackers to change the state of an order's adjustments if they hold its number, and the execution happens on a store administrator's computer. Users should upgrade to solidus_backend 3.1.6, 3.0.6, or 2.11.16 to receive a patch.

CVSS3: 2.3
EPSS: Низкий
github логотип

GHSA-8639-qx56-r428

больше 3 лет назад

CSRF allows attacker to finalize/unfinalize order adjustments in solidus_backend

CVSS3: 2.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-31000

solidus_backend is the admin interface for the Solidus e-commerce framework. Versions prior to 3.1.6, 3.0.6, and 2.11.16 contain a cross-site request forgery (CSRF) vulnerability. The vulnerability allows attackers to change the state of an order's adjustments if they hold its number, and the execution happens on a store administrator's computer. Users should upgrade to solidus_backend 3.1.6, 3.0.6, or 2.11.16 to receive a patch.

CVSS3: 2.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-8639-qx56-r428

CSRF allows attacker to finalize/unfinalize order adjustments in solidus_backend

CVSS3: 2.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу