PT-2004-2891 · Fusetalk · Fusetalk

·

CVE-2004-1995

·

Published

2004-12-31

·

Updated

2024-02-08

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions FuseTalk version 2.0
Description A Cross-Site Request Forgery (CSRF) issue allows remote attackers to create arbitrary accounts via a link to "adduser.cfm".
Recommendations For FuseTalk version 2.0, consider disabling the account creation functionality until a patch is available. Restrict access to the "adduser.cfm" endpoint to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2004-1995

Affected Products

Fusetalk