8.8
CVE-2022-46074
- EPSS 0.49%
- Veröffentlicht 14.12.2022 17:15:11
- Zuletzt bearbeitet 22.04.2025 03:15:19
- CVE-Watchlists
- Unerledigt
Helmet Store Showroom 1.0 is vulnerable to Cross Site Request Forgery (CSRF). An unauthenticated user can add an admin account due to missing CSRF protection.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Helmet Store Showroom Project ≫ Helmet Store Showroom Version1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.49% | 0.38 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| CISA-ADP | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
https://www.youtube.com/watch?v=5Q3vyTo02bc&ab_channel=IkariShinji
https://yuyudhn.github.io/CVE-2022-46074/