vendor:
ICE Hrm
by:
Piyush Patil & Rafal Lykowski
8,8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: ICE Hrm
Affected Version From: 29.0.0.OS
Affected Version To: 29.0.0.OS
Patch Exists: NO
Related CWE: N/A
CPE: a:icehrm:ice_hrm:29.0.0.os
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 10 and Kali
2020
ICE Hrm 29.0.0.OS – ‘Account Takeover’ Cross-Site Request Forgery (CSRF)
ICE Hrm Version 29.0.0.OS is vulnerable to CSRF which allows attacker to add new admin account or change the password leading to full account takeover.
Mitigation:
Implementing CSRF protection mechanisms such as CSRF tokens, SameSite cookies, and CORS.