CVE-2017-15608
Published Sep 26, 2018Inedo ProGet before 5.0 Beta5 has CSRF, allowing an attacker to change advanced settings.
Vendor/product archive
2 CVEs tagged to inedo / proget — 0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.
Inedo ProGet before 5.0 Beta5 has CSRF, allowing an attacker to change advanced settings.
Inedo ProGet before 4.7.14 does not properly address dangerous package IDs during package addition, aka PG-1060.