A Cross-Origin Resource Sharing (CORS) vulnerability found in UniFi Protect application Version 1.19.2 and earlier allows a malicious actor who has convinced a privileged user to access a URL with malicious code to take over said user’s account.This vulnerability is fixed in UniFi Protect application Version 1.20.0 and later.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: hackerone
Published: 2021-11-24T18:49:30
Updated: 2024-08-03T18:58:26.074Z
Reserved: 2021-01-06T00:00:00
Link: CVE-2021-22957
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-11-24T19:15:07.557
Modified: 2024-11-21T05:51:01.087
Link: CVE-2021-22957
Redhat
No data.