OpenSIS Classic Community Edition version 9.0 lacks cross-site request forgery (CSRF) protection throughout the whole app. This may allow an attacker to trick an authenticated user into performing any kind of state changing request.
History

Mon, 21 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-11-20T00:00:00

Updated: 2024-10-21T14:17:29.601Z

Reserved: 2023-07-25T00:00:00

Link: CVE-2023-38885

cve-icon Vulnrichment

Updated: 2024-08-02T17:54:39.276Z

cve-icon NVD

Status : Modified

Published: 2023-11-20T19:15:08.820

Modified: 2024-11-21T08:14:21.993

Link: CVE-2023-38885

cve-icon Redhat

No data.