PT-2018-4964 · Codelathe · Filecloud

Stéphane Adamiste

·

Published

2018-07-13

·

Updated

2022-04-22

·

CVE-2016-6578

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CodeLathe FileCloud versions 13.0.0.32841 and earlier
Description The issue allows an attacker to perform actions with the same permissions as a victim user, provided the victim has an active session and is induced to trigger the malicious request. This is due to a global cross-site request forgery (CSRF) vulnerability.
Recommendations For CodeLathe FileCloud versions 13.0.0.32841 and earlier, update to a version later than 13.0.0.32841 to resolve the issue. As a temporary workaround, consider implementing additional CSRF protection measures to minimize the risk of exploitation.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-6578

Affected Products

Filecloud