Description
Cross-Site Request Forgery vulnerability, whose exploitation could allow an attacker to perform different actions on the platform as an administrator, simply by changing the token value to "admin". It is also possible to perform POST, GET and DELETE requests without any token value. Therefore, an unprivileged remote user is able to create, delete and modify users within theapplication.
No analysis available yet.
Remediation
Vendor Solution
>The vulnerability has been fixed in the latest version.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-54511 | Cross-Site Request Forgery vulnerability, whose exploitation could allow an attacker to perform different actions on the platform as an administrator, simply by changing the token value to "admin". It is also possible to perform POST, GET and DELETE requests without any token value. Therefore, an unprivileged remote user is able to create, delete and modify users within theapplication. |
References
History
Fri, 20 Sep 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-09-20T14:52:13.615Z
Reserved: 2023-08-31T07:09:09.454Z
Link: CVE-2023-4659
Updated: 2024-08-02T07:31:06.631Z
Status : Modified
Published: 2023-10-02T15:15:15.017
Modified: 2024-11-21T08:35:37.813
Link: CVE-2023-4659
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD