OSV 1.4.0 · github-reviewed · 修改于 2022-02-01 05:47
发布时间
2022-01-28 00:21
GitHub 审查时间
2022-01-26 05:09
NVD 发布时间
2022-01-24 20:15
源文件
advisories/github-reviewed/2022/01/GHSA-7g7r-gr46-q4p5/GHSA-7g7r-gr46-q4p5.json
Versions of yetiforce 6.3.0 and prior are subject to privilege escalation via a cross site request forgery bug. This allows an attacker to create a new admin account even with SameSite: Strict enabled. This vulnerability can be exploited by any user on the system including guest users.