Impact
This vulnerability is a Cross-Site Request Forgery weakness in the Administrative Console of PingFederate in versions prior to 13.1. It allows an attacker to cause a logged-in administrator to submit requests that perform privileged actions. The weakness is identified as CWE-352 and is limited to actions that require administrator privileges.
Affected Systems
The affected product is Ping Identity PingFederate. All releases before version 13.1 are vulnerable, regardless of operating system, as reflected by the listed CPE entries for 64‑bit, Linux, and Windows builds.
Risk and Exploitability
The CVSS score of 4.9 indicates a moderate severity. No EPSS data is available, and the vulnerability is not in the CISA KEV catalog. The attack most likely requires a victim administrator to click a malicious link or otherwise submit a forged request while an authenticated session is active. If successful, the attacker can perform any action that the administrator is authorized to perform.
OpenCVE Enrichment