Description
An issue was discovered in Hyland OnBase through 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. CSRF can be used to log in a user, and then perform actions, because there are default credentials (the wstinol password for the manager or hsi account).
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-17942 | An issue was discovered in Hyland OnBase through 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. CSRF can be used to log in a user, and then perform actions, because there are default credentials (the wstinol password for the manager or hsi account). |
References
| Link | Providers |
|---|---|
| https://seclists.org/fulldisclosure/2020/Sep/9 |
|
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T15:33:05.463Z
Reserved: 2020-09-11T00:00:00.000Z
Link: CVE-2020-25252
No data.
Status : Modified
Published: 2020-09-11T03:15:12.630
Modified: 2024-11-21T05:17:46.280
Link: CVE-2020-25252
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD