CVE-2021-29995
HIGHCloverDX <5.9.0 - CSRF
Title source: llmDescription
A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute any action as the logged-in user (including script execution). The issue is resolved in CloverDX 5.10, CloverDX 5.9.1, CloverDX 5.8.2, and CloverDX 5.7.1.
Exploits (1)
References (3)
Scores
CVSS v3
8.8
EPSS
0.0173
EPSS Percentile
82.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-352
Status
published
Products (1)
cloverdx/cloverdx
< 5.7.1
Published
Jun 09, 2021
Tracked Since
Feb 18, 2026