vendor:
GV-ASManager
by:
Giorgi Dograshvili [DRAGOWN]
6.1
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: GV-ASManager
Affected Version From: 6.1.1.0
Affected Version To: 6.1.1.0
Patch Exists: NO
Related CWE: CVE-2024-56901
CPE: a:geovision:gv-asmanager:6.1.1.0
Platforms Tested: Windows 10, Kali Linux
2025
GeoVision GV-ASManager 6.1.1.0 – CSRF
A CSRF vulnerability exists in GeoVision GV-ASManager web application version 6.1.1.0 or earlier, enabling attackers to create Admin accounts via a crafted GET request. This exploit is often combined with CVE-2024-56903 for a successful CSRF attack.
Mitigation:
To mitigate this vulnerability, it is recommended to implement anti-CSRF tokens, validate user inputs, and employ secure coding practices to prevent unauthorized actions.