Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:45725
HistoryMar 02, 2024 - 9:24 p.m.

Cross-site Request Forgery (CSRF)

2024-03-0221:24:53
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7
csrf
phppgadmin
vulnerability
remote attackers
arbitrary system commands

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

9.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

AI Score

7.5

Confidence

Low

EPSS

0.003

Percentile

69.7%

phpPgAdmin is vulnerable to Cross-Site Request Forgery (CSRF). The vulnerability is due to insufficient validation of the request source in the “database.php” area of phpPgAdmin. This allows sensitive actions to be performed without proper verification of the request’s origin. A remote attacker can exploit this by tricking a logged-in administrator into visiting a malicious page with a CSRF exploit, enabling them to execute arbitrary system commands on the server.

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

9.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

AI Score

7.5

Confidence

Low

EPSS

0.003

Percentile

69.7%