PT-2021-15495 · Unknown · Sqlite-Web

Yadhu Krishna M

·

Published

2021-09-08

·

Updated

2021-09-14

·

CVE-2021-23404

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions sqlite-web versions (all versions)
Description The issue concerns a lack of validation for requests in the SQL dashboard area, allowing sensitive actions to be performed without proper verification of the request's origin. This could enable an attacker to trick a user into performing unintended actions through a Cross Site Request Forgery (CSRF) attack.
Recommendations For all versions, consider implementing proper request validation to ensure that actions in the SQL dashboard area originate from the application, mitigating the risk of CSRF attacks. As a temporary workaround, restrict access to the SQL dashboard area to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-23404
GHSA-2J58-PWWV-X666
PYSEC-2021-332
SNYK-PYTHON-SQLITEWEB-1316324

Affected Products

Sqlite-Web