Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
4.3
CVE-2023-52060
- EPSS 0.26%
- Veröffentlicht 13.02.2024 01:15:08
- Zuletzt bearbeitet 13.03.2025 20:15:16
A Cross-Site Request Forgery (CSRF) in Gestsup v3.2.46 allows attackers to arbitrarily edit user profile information via a crafted request.
9.8
CVE-2021-31646
- EPSS 1.34%
- Veröffentlicht 26.04.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:06:04
Gestsup before 3.2.10 allows account takeover through the password recovery functionality (remote). The affected component is the file forgot_pwd.php - it uses a weak algorithm for the generation of password recovery tokens (the PHP uniqueid function...