A Cross-Site Request Forgery (CSRF) vulnerability affecting Teamwork Cloud from No Magic Release 2021x through No Magic Release 2022x could allow with some very specific conditions an attacker to send a specifically crafted query to the server.
History

Thu, 19 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Dassault
Dassault teamwork Cloud Enterprise Edition
Dassault teamwork Cloud Standard Edition
Dassult
Dassult teamwork Cloud Business Edition
Dassult teamwork Cloud Business Pro Edition
CPEs cpe:2.3:a:dassault:teamwork_cloud_enterprise_edition:*:*:*:*:*:*:*:*
cpe:2.3:a:dassault:teamwork_cloud_standard_edition:*:*:*:*:*:*:*:*
cpe:2.3:a:dassult:teamwork_cloud_business_edition:*:*:*:*:*:*:*:*
cpe:2.3:a:dassult:teamwork_cloud_business_pro_edition:*:*:*:*:*:*:*:*
Vendors & Products Dassault
Dassault teamwork Cloud Enterprise Edition
Dassault teamwork Cloud Standard Edition
Dassult
Dassult teamwork Cloud Business Edition
Dassult teamwork Cloud Business Pro Edition
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: 3DS

Published: 2023-10-09T08:54:08.100Z

Updated: 2024-09-19T14:58:42.152Z

Reserved: 2023-07-10T14:22:56.221Z

Link: CVE-2023-3589

cve-icon Vulnrichment

Updated: 2024-08-02T07:01:56.455Z

cve-icon NVD

Status : Analyzed

Published: 2023-10-09T09:15:10.507

Modified: 2023-10-20T20:22:07.120

Link: CVE-2023-3589

cve-icon Redhat

No data.