Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ludovic Ortega

#29288of 53,635
8.8Total CVSS
Vulnerabilities · 1
PT-2020-15624
8.8
2020-10-22
Fs.Com · Fs.Com S3900 24T4S · CVE-2020-24033
**Name of the Vulnerable Software and Affected Versions** fs.com S3900 24T4S versions 1.7.0 and earlier **Description** An issue was discovered that allows remote attackers to forge requests on behalf of a site administrator, enabling them to change all settings, including deleting users and creating new users with escalated privileges, due to the lack of an authentication or token authentication mechanism in the form. **Recommendations** For fs.com S3900 24T4S versions 1.7.0 and earlier, consider implementing an authentication or token authentication mechanism in the form to prevent remote attackers from forging requests. As a temporary workaround, restrict access to the form and settings to minimize the risk of exploitation.