PT-2022-21227 · Ferdi+1 · Ferdi+1

Omriinbar-Cyesec

·

Published

2022-07-17

·

Updated

2022-07-25

·

CVE-2022-32320

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ferdi versions through 5.8.1 Ferdium versions through 6.0.0-nightly.98
Description A Cross-Site Request Forgery (CSRF) issue allows attackers to read files via an uploaded file, such as a settings or preferences file.
Recommendations For Ferdi versions through 5.8.1, update to a version later than 5.8.1 to resolve the issue. For Ferdium versions through 6.0.0-nightly.98, update to a version later than 6.0.0-nightly.98 to resolve the issue. As a temporary workaround, consider restricting the upload of files to minimize the risk of exploitation.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-32320

Affected Products

Ferdi
Ferdium