ZeroHour

CVE-2018-20595

PoC
CVSS 3.0
8.8 high
EPSS
<1%p49
Published
()
Modified
Description

A CSRF issue was discovered in web/authorization/oauth2/controller/OAuth2ClientController.java in hsweb 3.0.4 because the state parameter in the request is not compared with the state parameter in the session after user authentication is successful.

Vendors
hsweb
Products
hsweb
Weakness
CWE-352
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.