CVE-2022-32320
Severity CVSS v4.0:
Pending analysis
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
17/07/2022
Last modified:
25/07/2022
Description
A Cross-Site Request Forgery (CSRF) in Ferdi through 5.8.1 and Ferdium through 6.0.0-nightly.98 allows attackers to read files via an uploaded file such as a settings/preferences file.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ferdium:ferdium:6.0.0:-:*:*:*:*:*:* | ||
| cpe:2.3:a:ferdium:ferdium:6.0.0:beta1:*:*:*:*:*:* | ||
| cpe:2.3:a:ferdium:ferdium:6.0.0:beta2:*:*:*:*:*:* | ||
| cpe:2.3:a:ferdium:ferdium:6.0.0:beta3:*:*:*:*:*:* | ||
| cpe:2.3:a:ferdium:ferdium:6.0.0:nightly1:*:*:*:*:*:* | ||
| cpe:2.3:a:ferdium:ferdium:6.0.0:nightly10:*:*:*:*:*:* | ||
| cpe:2.3:a:ferdium:ferdium:6.0.0:nightly11:*:*:*:*:*:* | ||
| cpe:2.3:a:ferdium:ferdium:6.0.0:nightly12:*:*:*:*:*:* | ||
| cpe:2.3:a:ferdium:ferdium:6.0.0:nightly13:*:*:*:*:*:* | ||
| cpe:2.3:a:ferdium:ferdium:6.0.0:nightly14:*:*:*:*:*:* | ||
| cpe:2.3:a:ferdium:ferdium:6.0.0:nightly15:*:*:*:*:*:* | ||
| cpe:2.3:a:ferdium:ferdium:6.0.0:nightly16:*:*:*:*:*:* | ||
| cpe:2.3:a:ferdium:ferdium:6.0.0:nightly17:*:*:*:*:*:* | ||
| cpe:2.3:a:ferdium:ferdium:6.0.0:nightly18:*:*:*:*:*:* | ||
| cpe:2.3:a:ferdium:ferdium:6.0.0:nightly19:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



