PT-2021-11093 · Quadbase · Quadbase Espressreports Es

Published

2021-03-11

·

Updated

2021-03-19

·

CVE-2020-24983

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Quadbase EspressReports ES version 7 Update 9
Description: An issue allows an unauthenticated attacker to create a malicious HTML file that houses a POST request made to the "DashboardBuilder" within the target web application. This request utilizes the target admin session and performs the authenticated request, such as changing the Dashboard name, as if the victim had done so themselves, also known as a Cross-Site Request Forgery (CSRF) attack.
Recommendations: For Quadbase EspressReports ES version 7 Update 9, consider implementing CSRF protection mechanisms, such as token-based validation, to prevent unauthorized requests. As a temporary workaround, restrict access to the DashboardBuilder feature to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-24983

Affected Products

Quadbase Espressreports Es