CVE-2023-4659

CVE-2023-4659

Cross-Site Request Forgery vulnerability, whose exploitation could allow an attacker to perform different actions on the platform as an administrator, simply by changing the token value to "admin". It is also possible to perform POST, GET and DELETE requests without any token value. Therefore, an unprivileged remote user is able to create, delete and modify users within theapplication.

Source: CVE-2023-4659

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다