Lucene search

K
cvelistMitreCVELIST:CVE-2017-8930
HistoryMay 14, 2017 - 10:00 p.m.

CVE-2017-8930

2017-05-1422:00:00
mitre
www.cve.org
4
cve-2017-8930
cross-site request forgery
remote attackers
admin authentication
hijack
user accounts
application takeover
configuration parameters
tax rates
paypal payment

AI Score

9.1

Confidence

High

EPSS

0.001

Percentile

40.9%

Multiple cross-site request forgery (CSRF) vulnerabilities in Simple Invoices 2013.1.beta.8 allow remote attackers to hijack the authentication of admins for requests that can (1) create new administrator user accounts and take over the entire application, (2) create regular user accounts, or (3) change configuration parameters such as tax rates and the enable/disable status of PayPal payment modules.

AI Score

9.1

Confidence

High

EPSS

0.001

Percentile

40.9%

Related for CVELIST:CVE-2017-8930