Cross-site request forgery (CSRF) vulnerability in Fujitsu e-Pares V01 L01 V01 L01, L03, L10, L20, L30, and L40 allows remote attackers to hijack the authentication of users for requests that modify "facility reservation data" via unknown vectors.
📦
e-pares
Vendor: fujitsu
Actively Exploited
0
CISA KEV List
PoC / Exploits
0
Code Available
Total RCEs
0
Remote Access
Total CVEs
678
Total Indexed
Avg. EPSS
1.40%
Exploit Prob.
Security Vulnerability Index
Page 1 / 68
2.6
CVSS
Severity: LOW
4.3
CVSS
Cross-site scripting (XSS) vulnerability Fujitsu e-Pares V01 L01 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Severity: MEDIUM
4.0
CVSS
Session fixation vulnerability in Fujitsu e-Pares V01 L01, L03, L10, L20, L30 allows remote attackers to hijack web sessions via unspecified vectors.
Severity: MEDIUM