CVE-2024-27631
MEDIUM 6.0EPSS 0.4%
Cross Site Request Forgery vulnerability in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via siteadmin/usergroup.php
- CVSS v3.1
- 6.0 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L - EPSS
- 0.42% chance of exploitation in the next 30 days, 35th percentile
- Published
- 2024-04-08
- Updated
- 2024-08-28
Proof-of-concept exploits (2)
- ally-petitt/CVE-2024-276310★ · 2024-04-07
- https://medium.com/%40allypetitt/how-i-found-3-cves-in-2-days-8a135eb924d3