PT-2021-10512 · Opms · Opms
Published
2021-12-22
·
Updated
2021-12-23
·
CVE-2020-20595
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
OPMS versions 1.3 and below
Description:
A cross-site request forgery (CSRF) issue allows attackers to arbitrarily add a user account via the "/user/add" API endpoint. This enables unauthorized modifications to the system by tricking users into performing unintended actions.
Recommendations:
For OPMS versions 1.3 and below, as a temporary workaround, consider restricting access to the "/user/add" API endpoint until a patch is available. Additionally, implement proper CSRF token validation to prevent unauthorized requests.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opms