A Cross-Site Request Forgery (CSRF) in IceHrm 31.0.0.OS allows attackers to delete arbitrary users or achieve account takeover via the app/service.php URI.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-04-08T20:12:28

Updated: 2024-08-03T05:03:33.115Z

Reserved: 2022-03-07T00:00:00

Link: CVE-2022-26588

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-04-08T21:15:08.377

Modified: 2024-11-21T06:54:10.277

Link: CVE-2022-26588

cve-icon Redhat

No data.