Impact
A flaw in RackTables up to 0.22.0 permits attackers to forge cross‑site requests because the application lacks CSRF protections. By tricking an authenticated user into submitting a crafted request, an attacker could initiate state‑changing operations such as modifying configuration or inventory data. The weakness is rooted in missing CSRF tokens (CWE‑352) and inadequate authorization checks (CWE‑862).
Affected Systems
RackTables, specifically all releases up to and including 0.22.0 (commit e5fff9f8aab339798ed47e8c6d7d977ed97a82bd). No other vendors or products are listed.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity, and the vulnerability is not yet in CISA’s KEV list. EPSS information is unavailable, so the precise likelihood of exploitation cannot be quantified, but the lack of CSRF defenses means virtually any browser session could be abused from a remote web page. Therefore, the risk is moderate to high for environments where RackTables is exposed to the Internet and users may be susceptible to phishing or malicious content.
OpenCVE Enrichment