vendor:
SolarWinds N-central
by:
7.5
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: SolarWinds N-central
Affected Version From: 8.0.1
Affected Version To: 8.2.0-1152
Patch Exists: NO
Related CWE:
CPE: a:SolarWinds:SolarWinds_N-central
Platforms Tested:
Cross-Site Request Forgery Vulnerability in N-central
A remote attacker can perform certain administrative actions and gain unauthorized access to the affected application by exploiting this vulnerability. Other attacks are also possible.
Mitigation:
Implement measures to verify the authenticity of requests, such as CSRF tokens or referrer validation. Regularly update to the latest version of N-central.