PT-2022-27732 · Unknown · Helmet Store Showroom

·

CVE-2022-46074

·

Published

2022-12-14

·

Updated

2023-01-30

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Helmet Store Showroom version 1.0
Description The issue allows an unauthenticated user to add an admin account due to missing Cross Site Request Forgery (CSRF) protection. This enables an attacker to perform actions on behalf of other users without their knowledge or consent.
Recommendations For Helmet Store Showroom version 1.0, consider implementing proper CSRF protection mechanisms to prevent unauthorized actions. As a temporary workaround, restrict access to admin account creation functionality until a patch is available.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-46074

Affected Products

Helmet Store Showroom