PT-2022-27732 · Unknown · Helmet Store Showroom

Yuyudhn

·

Published

2022-12-14

·

Updated

2023-01-30

·

CVE-2022-46074

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Helmet Store Showroom version 1.0
Description The issue allows an unauthenticated user to add an admin account due to missing Cross Site Request Forgery (CSRF) protection. This enables an attacker to perform actions on behalf of other users without their knowledge or consent.
Recommendations For Helmet Store Showroom version 1.0, consider implementing proper CSRF protection mechanisms to prevent unauthorized actions. As a temporary workaround, restrict access to admin account creation functionality until a patch is available.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2022-46074

Affected Products

Helmet Store Showroom