PT-2022-27732 · Unknown · Helmet Store Showroom
Yuyudhn
·
Published
2022-12-14
·
Updated
2023-01-30
·
CVE-2022-46074
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Helmet Store Showroom version 1.0
Description
The issue allows an unauthenticated user to add an admin account due to missing Cross Site Request Forgery (CSRF) protection. This enables an attacker to perform actions on behalf of other users without their knowledge or consent.
Recommendations
For Helmet Store Showroom version 1.0, consider implementing proper CSRF protection mechanisms to prevent unauthorized actions. As a temporary workaround, restrict access to admin account creation functionality until a patch is available.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Helmet Store Showroom