vendor:
FaceSentry Access Control System
by:
Gjoko 'LiquidWorm' Krstic
5.5
CVSS
MEDIUM
Cross-Site Request Forgery
352
CWE
Product Name: FaceSentry Access Control System
Affected Version From: Firmware 6.4.8 build 264 (Algorithm A16), Firmware 5.7.2 build 568 (Algorithm A14), Firmware 5.7.0 build 539 (Algorithm A14)
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:iwt:ltd:facesentry_access_control_system:6.4.8
Platforms Tested: Linux, Ubuntu, lighttpd, Armbian, Sunxi Linux, Orange Pi PC +
2019
FaceSentry Access Control System 6.4.8 Cross-Site Request Forgery
The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.
Mitigation:
Implement proper validation and verification checks for all HTTP requests to prevent Cross-Site Request Forgery attacks.