PT-2021-23398 · Xstream · Stream
Omriinbar
·
Published
2021-09-29
·
Updated
2021-10-03
·
CVE-2021-41764
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Streama versions up to and including 1.10.3
Description
A cross-site request forgery (CSRF) vulnerability exists in the application. The application does not have CSRF checks in place when performing actions such as uploading local files. As a result, attackers could make a logged-in administrator upload arbitrary local files via a CSRF attack and send them to the attacker.
Recommendations
For versions up to and including 1.10.3, consider implementing CSRF checks for actions like uploading local files to prevent exploitation.
As a temporary workaround, restrict access to file upload functionality until a patch is available.
Avoid using the file upload feature in the affected application until the issue is resolved.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Stream