// For flags

CVE-2022-3582

SourceCodester Simple Cold Storage Management System cross-site request forgery

Severity Score

3.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A vulnerability has been found in SourceCodester Simple Cold Storage Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument change password leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-211189 was assigned to this vulnerability.

Se ha encontrado una vulnerabilidad en SourceCodester Simple Cold Storage Management System versión 1.0 y ha sido clasificada como problemática. Esta vulnerabilidad afecta a una funcionalidad desconocida. La manipulación del argumento cambio de contraseña conlleva a un ataque de tipo cross-site request forgery. El ataque puede ser lanzado remotamente. La explotación ha sido divulgada al público y puede ser usada. El identificador VDB-211189 fue asignado a esta vulnerabilidad

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-10-18 CVE Reserved
  • 2022-10-18 CVE Published
  • 2024-05-10 EPSS Updated
  • 2024-08-03 CVE Updated
  • 2024-08-03 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-352: Cross-Site Request Forgery (CSRF)
  • CWE-863: Incorrect Authorization
CAPEC
References (2)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Oretnom23
Search vendor "Oretnom23"
Simple Cold Storage Management System
Search vendor "Oretnom23" for product "Simple Cold Storage Management System"
1.0
Search vendor "Oretnom23" for product "Simple Cold Storage Management System" and version "1.0"
-
Affected