Impact
The flaw is a cross‑site request forgery (CSRF) in Flask‑MonitoringDashboard. Remote attackers can create requests that the server treats as authenticated, enabling execution of actions the victim’s account is allowed to perform. The CVE notes that some unknown functionality is affected, meaning the exact reach of the impact is not detailed in the description. The weakness types are CWE‑352 and CWE‑862.
Affected Systems
Any installation of Flask‑MonitoringDashboard version up to 5.0.2. The affected product is flask‑dashboard’s Flask‑MonitoringDashboard web‑based monitoring interface.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of <1% shows that exploitation is considered very unlikely at present. The vulnerability is not listed in the CISA KEV catalog. The attack vector appears to be remote, requiring the attacker to send crafted requests. Given the moderate score and low exploitation probability, the overall risk is present but can be mitigated by applying a patch or applying other mitigations. This vulnerability is classified as CWE‑352 and CWE‑862.
OpenCVE Enrichment