PT-2022-19586 · Unknown · Hermit 音乐播放器
Re-Alter
+1
·
Published
2022-04-28
·
Updated
2023-01-30
·
CVE-2022-29412
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Hermit 音乐播放器 plugin versions <= 3.1.6
Description
The issue concerns multiple Cross-Site Request Forgery (CSRF) vulnerabilities. These vulnerabilities allow attackers to perform various actions, such as deleting cache, deleting a source, and creating a source.
Recommendations
For Hermit 音乐播放器 plugin versions <= 3.1.6, update to a version higher than 3.1.6 to resolve the issue. As a temporary workaround, consider restricting access to sensitive functions that can be exploited through CSRF attacks, such as cache deletion, source deletion, and source creation.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hermit 音乐播放器