vendor:
CacheGuard-OS
by:
William Costa
7,5
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: CacheGuard-OS
Affected Version From: CacheGuard-OS v5.7.7
Affected Version To: CacheGuard-OS v5.7.7
Patch Exists: YES
Related CWE: N/A
CPE: a:cacheguard:cacheguard-os:5.7.7
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
CSRF vulnerabilities in CacheGuard-OS v5.7.7
A CSRF vulnerability has been detected in CacheGuard in '/gui/password-wadmin.apl'. The application does not validate the parameter any csrf_token '/gui/password-wadmin.apl'. This allows attackers to modify settings or change password of user administrator in CacheGuard, because these functions are not protected by CSRF-Tokens.
Mitigation:
All functions must be protected by CSRF-Tokens.