PT-2021-10704 · Unknown · Homeautomation
Gjoko Krstic
·
Published
2021-04-27
·
Updated
2021-05-06
·
CVE-2020-21989
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
HomeAutomation version 3.3.2
Description:
The issue allows users to perform certain actions via HTTP requests without validity checks, which can be exploited to perform actions with administrative privileges if a logged-in user visits a malicious web site. This is due to a Cross Site Request Forgery (CSRF) flaw in the application interface.
Recommendations:
For HomeAutomation version 3.3.2, consider implementing validity checks for HTTP requests to prevent unauthorized actions. As a temporary workaround, restrict access to administrative privileges until a patch is available.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Homeautomation