Lucene search

K
cveJpcertCVE-2021-20851
HistoryDec 01, 2021 - 3:15 a.m.

CVE-2021-20851

2021-12-0103:15:06
CWE-352
jpcert
web.nvd.nist.gov
20
cve-2021-20851
cross-site request forgery
csrf vulnerability
browser and operating system finder
nvd
security vulnerability
remote attacker hijacking authentication

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

46.4%

Cross-site request forgery (CSRF) vulnerability in Browser and Operating System Finder versions prior to 1.2 allows a remote unauthenticated attacker to hijack the authentication of an administrator via unspecified vectors.

Affected configurations

Nvd
Vulners
Node
browser_and_operating_system_finder_projectbrowser_and_operating_system_finderRange<1.2wordpress
VendorProductVersionCPE
browser_and_operating_system_finder_projectbrowser_and_operating_system_finder*cpe:2.3:a:browser_and_operating_system_finder_project:browser_and_operating_system_finder:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "product": "Browser and Operating System Finder",
    "vendor": "Aftab Muni",
    "versions": [
      {
        "status": "affected",
        "version": "versions prior to 1.2"
      }
    ]
  }
]

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

46.4%

Related for CVE-2021-20851