PT-2022-15812 · Unknown · Petereport
Alestorm980
·
Published
2022-03-03
·
Updated
2022-03-10
·
CVE-2022-23052
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
PeteReport version 0.5
Description
The issue allows an attacker to trick users into deleting users, products, reports, and findings on the application through a Cross Site Request Forgery (CSRF) vulnerability. This means an attacker can forge requests that appear to come from the user, potentially leading to unauthorized actions.
Recommendations
For PeteReport version 0.5, consider implementing proper CSRF protection mechanisms, such as token-based validation, to prevent attackers from tricking users into performing unintended actions. As a temporary workaround, restrict access to sensitive operations like deleting users, products, reports, and findings until a proper fix is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Petereport