PT-2020-12469 · Gambio · Gambio Gx
Gerbert Roitburd
·
Published
2020-07-28
·
Updated
2020-07-31
·
CVE-2020-10984
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Gambio GX versions prior to 4.0.1.0
Description
The issue allows for a CSRF attack on the admin/admin.php endpoint. This can be exploited by tricking an administrator into performing unintended actions on the Gambio GX platform.
Recommendations
For versions prior to 4.0.1.0, update to version 4.0.1.0 or later to resolve the issue. As a temporary workaround, consider implementing CSRF token validation for the
admin/admin.php endpoint to prevent unauthorized requests. Restrict access to the admin/admin.php endpoint to minimize the risk of exploitation.Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gambio Gx