We found results for “”
WS-2022-0417
Good to know:
Date: November 9, 2022
Unintended API key generation in froxlor/froxlor. The API keys sections are vulnerable to CSRF. The aggressor can generate the key on the admin's account without prior knowledge of admin credentials. The successful CSRF will generate new keys on the admin's account.
Language: PHP
Severity Score
Severity Score
Weakness Type (CWE)
Cross-Site Request Forgery (CSRF)
CWE-352Top Fix
Upgrade Version
Upgrade to version froxlor/froxlor - dev-plugin-feature;froxlor/froxlor - dev-main;froxlor/froxlor - dev-dependabot/npm_and_yarn/postcss-8.4.31;froxlor/froxlor - 0.10.30;froxlor/froxlor - 0.10.38.3;froxlor/froxlor - 0.10.24;froxlor/froxlor - 0.10.28;froxlor/froxlor - 0.10.x-dev
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | REQUIRED |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | HIGH |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


