vendor:
IceHrm
by:
Devansh Bordia
6.5
CVSS
MEDIUM
Cross-site Request Forgery (CSRF)
352
CWE
Product Name: IceHrm
Affected Version From: 31.0.0.OS
Affected Version To: 31.0.0.OS
Patch Exists: NO
Related CWE: CVE-2022-26588
CPE: a:gamonoid:icehrm:31.0.0.os
Platforms Tested: Windows 10
2022
ICEHRM 31.0.0.0S – Cross-site Request Forgery (CSRF) to Account Deletion
The application has an update password feature which has a CSRF vulnerability that allows an attacker to change the password of any arbitrary user leading to an account takeover.
Mitigation:
Implementing CSRF tokens in the application and validating them on the server side.