CSRF protection was not present in SquaredUp before version 4.6.0. A CSRF attack could have been possible by an administrator executing arbitrary code in a HTML dashboard tile via a crafted HTML page, or by uploading a malicious SVG payload into a dashboard.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2021-02-03T00:00:00
Updated: 2024-08-04T10:26:16.181Z
Reserved: 2020-02-25T00:00:00
Link: CVE-2020-9388
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-02-03T20:15:13.010
Modified: 2024-11-21T05:40:32.453
Link: CVE-2020-9388
Redhat
No data.