← volver
CVE-2025-48740

CVE-2025-48740

CVSS 5.9 MEDIUMEPSS 0.2%CWE-352
A Cross-Site Request Forgery (CSRF) vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 before 5.4.10, and 5.5.0 before 5.5.1 allows a remote attacker to trigger requests on their victim's behalf, if the attacker lures a privileged user, authenticated with basic authentication.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Productos afectados
StrangeBee · TheHive

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →