PT-2021-22266 · Unknown · Cliniccases

Published

2021-09-07

·

Updated

2021-09-11

·

CVE-2021-38705

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ClinicCases version 7.3.3
Description The issue allows for Cross-Site Request Forgery (CSRF) attacks, where an authenticated user following a malicious link can result in arbitrary actions being carried out with the privilege level of the targeted user. This can be exploited to create a secondary administrator account for the attacker.
Recommendations For ClinicCases version 7.3.3, as a temporary workaround, consider implementing additional validation for requests to prevent CSRF attacks, such as verifying the origin of requests or using tokens to validate user intentions. However, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-38705

Affected Products

Cliniccases