PT-2021-11093 · Quadbase · Quadbase Espressreports Es
Published
2021-03-11
·
Updated
2021-03-19
·
CVE-2020-24983
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Quadbase EspressReports ES version 7 Update 9
Description:
An issue allows an unauthenticated attacker to create a malicious HTML file that houses a POST request made to the "DashboardBuilder" within the target web application. This request utilizes the target admin session and performs the authenticated request, such as changing the Dashboard name, as if the victim had done so themselves, also known as a Cross-Site Request Forgery (CSRF) attack.
Recommendations:
For Quadbase EspressReports ES version 7 Update 9, consider implementing CSRF protection mechanisms, such as token-based validation, to prevent unauthorized requests. As a temporary workaround, restrict access to the DashboardBuilder feature to minimize the risk of exploitation.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quadbase Espressreports Es