perfSONAR 4.4.5 Cross Site Request Forgery...

- AV AC AU C I A
发布: 2022-11-30
修订: 2024-12-11

A partial blind cross site request forgery (CSRF) vulnerability exists in perfSONAR versions 4.x through 4.4.5 within the /perfsonar-graphs/ test results page. Parameters and values can be injected/passed via the URL parameter, forcing the client to connect unknowingly in the background to other sites via transparent XMLHTTPRequests. This partial blind CSRF bypasses the built-in whitelisting function in perfSONAR.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息