PT-2021-9091 · Scytl · Scytl Svote

Anthony Schneiter

+1

·

Published

2021-02-27

·

Updated

2021-03-05

·

CVE-2019-25023

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Scytl sVote version 2.1
Description An issue was discovered in Scytl sVote where the IP address from an X-Forwarded-For header, which can be manipulated client-side, is used for the internal application logs. This allows an attacker to inject wrong IP addresses into these logs.
Recommendations For Scytl sVote version 2.1, consider validating the IP address from the X-Forwarded-For header to prevent manipulation, or use an alternative method for logging IP addresses that is not susceptible to client-side manipulation. As a temporary workaround, restrict access to the internal application logs to minimize the risk of exploitation.

Exploit

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-25023

Affected Products

Scytl Svote