PT-2025-50232 · Openbmc · Openbmc
Published
2025-12-09
·
Updated
2025-12-19
·
CVE-2021-47702
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenBMCS version 2.4
Description
OpenBMCS version 2.4 contains a Cross-Site Request Forgery (CSRF) issue. An attacker can perform actions with administrative privileges by exploiting the
sendFeedback.php API endpoint. Attackers can submit malicious requests to trigger unintended actions, such as sending emails or modifying system settings.Recommendations
Apply any available updates or patches to address the issue in OpenBMCS version 2.4.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openbmc