PT-2022-19586 · Unknown · Hermit 音乐播放器

Re-Alter

+1

·

Published

2022-04-28

·

Updated

2023-01-30

·

CVE-2022-29412

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Hermit 音乐播放器 plugin versions <= 3.1.6
Description The issue concerns multiple Cross-Site Request Forgery (CSRF) vulnerabilities. These vulnerabilities allow attackers to perform various actions, such as deleting cache, deleting a source, and creating a source.
Recommendations For Hermit 音乐播放器 plugin versions <= 3.1.6, update to a version higher than 3.1.6 to resolve the issue. As a temporary workaround, consider restricting access to sensitive functions that can be exploited through CSRF attacks, such as cache deletion, source deletion, and source creation.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2022-29412

Affected Products

Hermit 音乐播放器