PT-2020-19259 · Topmanage · Topmanage Olk
Published
2020-02-18
·
Updated
2020-02-27
·
CVE-2020-6844
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TopManage OLK version 2020
Description
The issue allows for login CSRF to be chained with another vulnerability, potentially leading to the takeover of admin and user accounts.
Recommendations
For TopManage OLK version 2020, consider implementing additional security measures to prevent CSRF attacks, such as token-based validation for login requests, until a patch is available.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Topmanage Olk