PT-2020-18704 · Ignitenet · Ignitenet Helios Glinq
Published
2020-09-23
·
Updated
2020-09-29
·
CVE-2020-5783
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IgniteNet HeliOS GLinq version 2.2.1 r2961
Description
The login functionality in the affected software lacks CSRF protection mechanisms, which could potentially allow for unauthorized actions.
Recommendations
For version 2.2.1 r2961, consider implementing CSRF protection mechanisms to prevent unauthorized access. As a temporary workaround, restrict access to the login functionality to minimize the risk of exploitation.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ignitenet Helios Glinq