PT-2021-22266 · Unknown · Cliniccases
Published
2021-09-07
·
Updated
2021-09-11
·
CVE-2021-38705
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ClinicCases version 7.3.3
Description
The issue allows for Cross-Site Request Forgery (CSRF) attacks, where an authenticated user following a malicious link can result in arbitrary actions being carried out with the privilege level of the targeted user. This can be exploited to create a secondary administrator account for the attacker.
Recommendations
For ClinicCases version 7.3.3, as a temporary workaround, consider implementing additional validation for requests to prevent CSRF attacks, such as verifying the origin of requests or using tokens to validate user intentions. However, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cliniccases