ZeroHour

CVE-2021-27759

CVSS 3.1
6.5 medium
EPSS
<1%p22
Published
()
Modified
Description

This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intentionally. An attacker can cause a victim's browser to emit an HTTP request to an arbitrary URL in the application.

Vendors
hcltech
Products
bigfix inventory
Weakness
CWE-352, CWE-345
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.