PT-2020-14634 · Polarion · Polarion Subversion Webclient
Published
2020-09-09
·
Updated
2020-09-14
·
CVE-2020-15789
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Polarion Subversion Webclient (All versions)
Description
A Cross-Site Request Forgery (CSRF) attack is possible through the web interface if a user is tricked into accessing a malicious link. The attack requires user interaction by an authenticated user, potentially allowing an attacker to trigger actions via the web interface, including reading or modifying web application contents.
Recommendations
For all versions, consider implementing CSRF protection mechanisms, such as token-based validation, to prevent unauthorized actions. As a temporary workaround, restrict access to sensitive areas of the web interface to minimize the risk of exploitation.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Polarion Subversion Webclient