vendor:
Selea Targa IP OCR-ANPR Camera
by:
LiquidWorm
7.5
CVSS
HIGH
CSRF Add Admin
352
CWE
Product Name: Selea Targa IP OCR-ANPR Camera
Affected Version From: BLD201113005214
Affected Version To: BLD191021180140
Patch Exists: YES
Related CWE: CVE-2020-25862
CPE: h:selea:targa_ip_ocr-anpr_camera
Other Scripts:
N/A
Platforms Tested: None
2020
Selea Targa IP OCR-ANPR Camera – CSRF Add Admin
An attacker can exploit this vulnerability by tricking a logged-in user into clicking a malicious link. This malicious link will add an admin user to the application.
Mitigation:
The application should perform validity checks to verify the requests.