Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Haungtongfuo

#15386of 53,632
17.6Total CVSS
Vulnerabilities · 2
High
2
PT-2023-12275
8.8
2023-02-03
Imcat · Imcat · CVE-2021-36443
**Name of the Vulnerable Software and Affected Versions** imcat version 5.4 **Description** The issue allows remote attackers to escalate privilege via a lack of token verification, which is a result of a Cross Site Request Forgery vulnerability. **Recommendations** For imcat version 5.4, consider implementing token verification to prevent Cross Site Request Forgery attacks. As a temporary workaround, restrict access to sensitive operations that could be exploited through this vulnerability until a proper fix is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2023-12276
8.8
2023-02-03
Imcat · Imcat · CVE-2021-36444
**Name of the Vulnerable Software and Affected Versions** imcat version 5.4 **Description** A Cross Site Request Forgery (CSRF) issue allows remote attackers to gain escalated privileges. This is due to flaws in one-time token generation on the "add administrator" page. **Recommendations** For imcat version 5.4, consider disabling the add administrator functionality until a patch is available to prevent exploitation of the CSRF issue.