CVE-2020-24983

CVE-2020-24983

An issue was discovered in Quadbase EspressReports ES 7 Update 9. An unauthenticated attacker can create a malicious HTML file that houses a POST request made to the DashboardBuilder within the target web application. This request will utilise the target admin session and perform the authenticated request (to change the Dashboard name) as if the victim had done so themselves, aka CSRF.

Source: CVE-2020-24983

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다