PT-2020-18704 · Ignitenet · Ignitenet Helios Glinq

Published

2020-09-23

·

Updated

2020-09-29

·

CVE-2020-5783

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions IgniteNet HeliOS GLinq version 2.2.1 r2961
Description The login functionality in the affected software lacks CSRF protection mechanisms, which could potentially allow for unauthorized actions.
Recommendations For version 2.2.1 r2961, consider implementing CSRF protection mechanisms to prevent unauthorized access. As a temporary workaround, restrict access to the login functionality to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5783

Affected Products

Ignitenet Helios Glinq