vendor:
Helix Server
by:
Unknown
5.5
CVSS
MEDIUM
Cross-site Request Forgery
352
CWE
Product Name: Helix Server
Affected Version From: Helix Server 14.0.1.571
Affected Version To: Unknown (other versions may also be affected)
Patch Exists: NO
Related CWE: Not mentioned
CPE: a:helixserver:helix_server:14.0.1.571
Platforms Tested: Unknown
Unknown
Cross-site Request Forgery in Helix Server
An attacker can exploit this issue to perform unauthorized actions by enticing a logged-in user to visit a malicious site. They can trick the user into performing unintended actions on their behalf.
Mitigation:
Implementing anti-CSRF tokens, validating requests, and implementing strict referer checks can help mitigate this vulnerability.