Cross site request forgery in Kiteworks OwnCloud allows an unauthenticated attacker to forge requests. If a request has no Authorization header, it is created with an empty string as value by a rewrite rule. The CSRF check is done by comparing the header value to null, meaning that the existing CSRF check is bypassed in this case. An attacker can, for example, create a new administrator account if the request is executed in the browser of an authenticated victim.
History

Tue, 01 Oct 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Kiteworks
Kiteworks owncloud
CPEs cpe:2.3:a:kiteworks:owncloud:*:*:*:*:*:*:*:*
Vendors & Products Kiteworks
Kiteworks owncloud
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 01 Oct 2024 13:00:00 +0000

Type Values Removed Values Added
Description Cross site request forgery in Kiteworks OwnCloud allows an unauthenticated attacker to forge requests. If a request has no Authorization header, it is created with an empty string as value by a rewrite rule. The CSRF check is done by comparing the header value to null, meaning that the existing CSRF check is bypassed in this case. An attacker can, for example, create a new administrator account if the request is executed in the browser of an authenticated victim.
Title Cross Site Request Forgery in Kiteworks OwnCloud
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cirosec

Published: 2024-10-01T12:34:10.481Z

Updated: 2024-10-01T13:16:05.468Z

Reserved: 2024-08-05T10:46:30.916Z

Link: CVE-2023-7273

cve-icon Vulnrichment

Updated: 2024-10-01T13:16:00.337Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-01T13:15:02.463

Modified: 2024-10-04T13:51:25.567

Link: CVE-2023-7273

cve-icon Redhat

No data.