CVE-2021-27759
—CVSS 3.1
6.5 medium
EPSS
<1%p22
Published
()
Modified
Description
This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intentionally. An attacker can cause a victim's browser to emit an HTTP request to an arbitrary URL in the application.
- Vendors
- hcltech
- Products
- bigfix inventory
- Weakness
- CWE-352, CWE-345
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.