PT-2018-18757 · Open Audit · Open-Audit Professional
Nilesh Sapariya
+1
·
Published
2018-03-25
·
Updated
2020-08-24
·
CVE-2018-8979
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Open-AudIT Professional version 2.1
Description
The issue allows for Cross-Site Request Forgery (CSRF) attacks, which can be used to modify user accounts or inject XSS sequences. This can be achieved by manipulating the credentials URI.
Recommendations
For Open-AudIT Professional version 2.1, consider implementing CSRF protection mechanisms to prevent unauthorized modifications to user accounts and injection of XSS sequences. As a temporary workaround, restrict access to the credentials URI to minimize the risk of exploitation.
Exploit
Fix
CSRF
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Open-Audit Professional