Логотип exploitDog
bind:CVE-2022-46164
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-46164

Количество 2

Количество 2

nvd логотип

CVE-2022-46164

около 3 лет назад

NodeBB is an open source Node.js based forum software. Due to a plain object with a prototype being used in socket.io message handling a specially crafted payload can be used to impersonate other users and takeover accounts. This vulnerability has been patched in version 2.6.1. Users are advised to upgrade. Users unable to upgrade may cherry-pick commit `48d143921753914da45926cca6370a92ed0c46b8` into their codebase to patch the exploit.

CVSS3: 9.4
EPSS: Средний
github логотип

GHSA-rf3g-v8p5-p675

около 3 лет назад

NodeBB vulnerable to account takeover via prototype vulnerability

CVSS3: 9.4
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-46164

NodeBB is an open source Node.js based forum software. Due to a plain object with a prototype being used in socket.io message handling a specially crafted payload can be used to impersonate other users and takeover accounts. This vulnerability has been patched in version 2.6.1. Users are advised to upgrade. Users unable to upgrade may cherry-pick commit `48d143921753914da45926cca6370a92ed0c46b8` into their codebase to patch the exploit.

CVSS3: 9.4
62%
Средний
около 3 лет назад
github логотип
GHSA-rf3g-v8p5-p675

NodeBB vulnerable to account takeover via prototype vulnerability

CVSS3: 9.4
62%
Средний
около 3 лет назад

Уязвимостей на страницу