Lucene search

K
nvd[email protected]NVD:CVE-2022-34937
HistoryAug 03, 2022 - 1:15 a.m.

CVE-2022-34937

2022-08-0301:15:07
CWE-352
web.nvd.nist.gov
3
yuba u5cms
csrf
code execution
vulnerability
savepage.php

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

46.4%

Yuba u5cms v8.3.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component savepage.php. This vulnerability allows attackers to execute arbitrary code.

Affected configurations

Nvd
Node
yubau5cmsMatch8.3.5
VendorProductVersionCPE
yubau5cms8.3.5cpe:2.3:a:yuba:u5cms:8.3.5:*:*:*:*:*:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

46.4%

Related for NVD:CVE-2022-34937