PT-2021-9091 · Scytl · Scytl Svote
Anthony Schneiter
+1
·
Published
2021-02-27
·
Updated
2021-03-05
·
CVE-2019-25023
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Scytl sVote version 2.1
Description
An issue was discovered in Scytl sVote where the IP address from an X-Forwarded-For header, which can be manipulated client-side, is used for the internal application logs. This allows an attacker to inject wrong IP addresses into these logs.
Recommendations
For Scytl sVote version 2.1, consider validating the IP address from the X-Forwarded-For header to prevent manipulation, or use an alternative method for logging IP addresses that is not susceptible to client-side manipulation. As a temporary workaround, restrict access to the internal application logs to minimize the risk of exploitation.
Exploit
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Scytl Svote