vendor:
TEM Opera Plus FM Family Transmitter
by:
Gjoko 'LiquidWorm' Krstic
6.1
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: TEM Opera Plus FM Family Transmitter
Affected Version From: 35.45
Affected Version To: 35.45
Patch Exists: NO
Related CWE: CVE-2023-XXXX (not provided in the text)
CPE: h:telecomunicazioni_elettro_milano:tem_opera_plus_fm_family_transmitter:35.45
Platforms Tested: Webserver
2023
TEM Opera Plus FM Family Transmitter 35.45 XSRF
The TEM Opera Plus FM Family Transmitter 35.45 devices are vulnerable to Cross-Site Request Forgery (CSRF) attacks. An attacker can exploit this vulnerability by tricking a logged-in user to visit a malicious website, leading to unauthorized actions being performed with administrative privileges.
Mitigation:
To mitigate this vulnerability, it is recommended to implement proper CSRF tokens and validation checks to ensure that requests are legitimate and originated from the expected source.