Page 2 of 6 results (0.001 seconds)

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 2

Open-AudIT Professional 2.1 has CSRF, as demonstrated by modifying a user account or inserting XSS sequences via the credentials URI. Open-AudIT Professional 2.1 contiene Cross-Site Request Forgery (CSRF), como ha sido demostrado modificando una cuenta de usuario o insertando secuencias XSS mediante las credenciales URI. Open-AuditIT Professional version 2.1 suffers from a cross site request forgery vulnerability. • https://www.exploit-db.com/exploits/44360 https://nileshsapariya.blogspot.ae/2018/03/csrf-to-xss-open-auditit-professional-21.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-352: Cross-Site Request Forgery (CSRF) •