5.4

CVE-2022-32175

Exploit

In AdGuardHome, versions v0.95 through v0.108.0-b.13 are vulnerable to Cross-Site Request Forgery (CSRF), in the custom filtering rules functionality. An attacker can persuade an authorized user to follow a malicious link, resulting in deleting/modifying the custom filtering rules.

Data is provided by the National Vulnerability Database (NVD)
AdguardAdguardhome Version >= 0.95 < 0.108
AdguardAdguardhome Version0.108 Update-
AdguardAdguardhome Version0.108 Updatebeta1
AdguardAdguardhome Version0.108 Updatebeta10
AdguardAdguardhome Version0.108 Updatebeta11
AdguardAdguardhome Version0.108 Updatebeta12
AdguardAdguardhome Version0.108 Updatebeta2
AdguardAdguardhome Version0.108 Updatebeta3
AdguardAdguardhome Version0.108 Updatebeta4
AdguardAdguardhome Version0.108 Updatebeta5
AdguardAdguardhome Version0.108 Updatebeta6
AdguardAdguardhome Version0.108 Updatebeta7
AdguardAdguardhome Version0.108 Updatebeta8
AdguardAdguardhome Version0.108 Updatebeta9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.166
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.4 2.8 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.4 2.8 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.