PT-2017-8773 · Jantek · Jantek Jtc-200
Karn Ganeshan
·
Published
2017-10-13
·
Updated
2017-11-03
·
CVE-2016-5789
CVSS v2.0
6.0
Medium
| Vector | AV:N/AC:M/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
JanTek JTC-200 (all versions)
Description
A Cross-site Request Forgery issue allows an attacker to perform actions with the same permissions as a victim user, provided the victim has an active session and is induced to trigger the malicious request.
Recommendations
For all versions, consider implementing measures to prevent Cross-site Request Forgery attacks, such as validating request origins and using anti-CSRF tokens, until a patch is available.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jantek Jtc-200