PT-2021-10182 · Video · Video
Richard1266
·
Published
2021-08-12
·
Updated
2021-08-17
·
CVE-2020-18463
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Video software version 2.0.0
Description:
A Cross Site Request Forgery (CSRF) issue exists, allowing a malicious user to delete a video message. This is related to the
video list.php file.Recommendations:
For version 2.0.0, consider implementing proper CSRF token validation to prevent unauthorized actions, such as deleting video messages, until a patch is available. As a temporary workaround, restrict access to the
video list.php file to minimize the risk of exploitation.Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Video