Description
OpenSIS Classic Community Edition version 9.0 lacks cross-site request forgery (CSRF) protection throughout the whole app. This may allow an attacker to trick an authenticated user into performing any kind of state changing request.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-42652 | OpenSIS Classic Community Edition version 9.0 lacks cross-site request forgery (CSRF) protection throughout the whole app. This may allow an attacker to trick an authenticated user into performing any kind of state changing request. |
References
History
Mon, 21 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-21T14:17:29.601Z
Reserved: 2023-07-25T00:00:00.000Z
Link: CVE-2023-38885
Updated: 2024-08-02T17:54:39.276Z
Status : Modified
Published: 2023-11-20T19:15:08.820
Modified: 2024-11-21T08:14:21.993
Link: CVE-2023-38885
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD