Bhima version 1.27.0 allows a remote attacker to update the privileges of any account registered in the application via a malicious link sent to an administrator. This is possible because the application is vulnerable to CSRF.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Fluid Attacks
Published: 2023-04-05T00:00:00
Updated: 2024-08-02T05:32:45.907Z
Reserved: 2023-02-22T00:00:00
Link: CVE-2023-0959
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-04-05T20:15:07.557
Modified: 2024-11-21T07:38:11.160
Link: CVE-2023-0959
Redhat
No data.