PT-2021-10512 · Opms · Opms

Published

2021-12-22

·

Updated

2021-12-23

·

CVE-2020-20595

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: OPMS versions 1.3 and below
Description: A cross-site request forgery (CSRF) issue allows attackers to arbitrarily add a user account via the "/user/add" API endpoint. This enables unauthorized modifications to the system by tricking users into performing unintended actions.
Recommendations: For OPMS versions 1.3 and below, as a temporary workaround, consider restricting access to the "/user/add" API endpoint until a patch is available. Additionally, implement proper CSRF token validation to prevent unauthorized requests.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-20595

Affected Products

Opms