PT-2021-23398 · Xstream · Stream

Omriinbar

·

Published

2021-09-29

·

Updated

2021-10-03

·

CVE-2021-41764

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Streama versions up to and including 1.10.3
Description A cross-site request forgery (CSRF) vulnerability exists in the application. The application does not have CSRF checks in place when performing actions such as uploading local files. As a result, attackers could make a logged-in administrator upload arbitrary local files via a CSRF attack and send them to the attacker.
Recommendations For versions up to and including 1.10.3, consider implementing CSRF checks for actions like uploading local files to prevent exploitation. As a temporary workaround, restrict access to file upload functionality until a patch is available. Avoid using the file upload feature in the affected application until the issue is resolved.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41764

Affected Products

Stream