PT-2021-10182 · Video · Video

Richard1266

·

Published

2021-08-12

·

Updated

2021-08-17

·

CVE-2020-18463

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Video software version 2.0.0
Description: A Cross Site Request Forgery (CSRF) issue exists, allowing a malicious user to delete a video message. This is related to the video list.php file.
Recommendations: For version 2.0.0, consider implementing proper CSRF token validation to prevent unauthorized actions, such as deleting video messages, until a patch is available. As a temporary workaround, restrict access to the video list.php file to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-18463

Affected Products

Video