PT-2020-14229 · Openmage · Openmage
Flyingmana
+1
·
Published
2020-08-19
·
Updated
2024-03-06
·
CVE-2020-15151
CVSS v3.1
8.0
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
OpenMage versions prior to 19.4.6
OpenMage versions prior to 20.0.2
Description
This issue allows attackers to circumvent the
fromkey protection in the Admin Interface, increasing the attack surface for Cross Site Request Forgery attacks.Recommendations
For versions prior to 19.4.6, update to version 19.4.6 or later.
For versions prior to 20.0.2, update to version 20.0.2 or later.
As a temporary workaround, consider restricting access to the Admin Interface to minimize the risk of exploitation.
Fix
CSRF
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openmage