PT-2025-50232 · Openbmc · Openbmc

Published

2025-12-09

·

Updated

2025-12-19

·

CVE-2021-47702

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenBMCS version 2.4
Description OpenBMCS version 2.4 contains a Cross-Site Request Forgery (CSRF) issue. An attacker can perform actions with administrative privileges by exploiting the sendFeedback.php API endpoint. Attackers can submit malicious requests to trigger unintended actions, such as sending emails or modifying system settings.
Recommendations Apply any available updates or patches to address the issue in OpenBMCS version 2.4.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2021-47702

Affected Products

Openbmc