CSRF protection was not present in SquaredUp before version 4.6.0. A CSRF attack could have been possible by an administrator executing arbitrary code in a HTML dashboard tile via a crafted HTML page, or by uploading a malicious SVG payload into a dashboard.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-02-03T00:00:00

Updated: 2024-08-04T10:26:16.181Z

Reserved: 2020-02-25T00:00:00

Link: CVE-2020-9388

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-02-03T20:15:13.010

Modified: 2023-02-23T00:15:10.693

Link: CVE-2020-9388

cve-icon Redhat

No data.