PT-2022-15812 · Unknown · Petereport

Alestorm980

·

Published

2022-03-03

·

Updated

2022-03-10

·

CVE-2022-23052

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions PeteReport version 0.5
Description The issue allows an attacker to trick users into deleting users, products, reports, and findings on the application through a Cross Site Request Forgery (CSRF) vulnerability. This means an attacker can forge requests that appear to come from the user, potentially leading to unauthorized actions.
Recommendations For PeteReport version 0.5, consider implementing proper CSRF protection mechanisms, such as token-based validation, to prevent attackers from tricking users into performing unintended actions. As a temporary workaround, restrict access to sensitive operations like deleting users, products, reports, and findings until a proper fix is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-23052

Affected Products

Petereport