CVE-2020-25263 - CERT CVE
ID CVE-2020-25263
Sažetak PyroCMS 3.7 is vulnerable to cross-site request forgery (CSRF) via the admin/addons/uninstall/anomaly.module.blocks URI: an arbitrary plugin will be deleted.
Reference
CVSS
Base: 5.8
Impact: 4.9
Exploitability:8.6
Pristup
VektorSloženostAutentikacija
NETWORK MEDIUM NONE
Impact
PovjerljivostCjelovitostDostupnost
NONE PARTIAL PARTIAL
CVSS vektor AV:N/AC:M/Au:N/C:N/I:P/A:P
Zadnje važnije ažuriranje 19-10-2020 - 18:44
Objavljeno 08-10-2020 - 13:15