8.8
CVSSv3

CVE-2021-29995

Published: 09/06/2021 Updated: 25/05/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX up to and including 5.9.0 allows remote malicious users to execute any action as the logged-in user (including script execution). The issue is resolved in CloverDX 5.10, CloverDX 5.9.1, CloverDX 5.8.2, and CloverDX 5.7.1.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cloverdx cloverdx

Exploits

CloverDX version 590 cross site request forgery to remote code execution exploit ...