vendor:
WARP / IPVPN / MPVPN
by:
LiquidWorm
8,8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: WARP / IPVPN / MPVPN
Affected Version From: WARP / IPVPN / MPVPN 10.2.2r38
Affected Version To: WARP / IPVPN / MPVPN 5.2.0r34
Patch Exists: NO
Related CWE: N/A
CPE: a:fatpipe_networks:warp/ipvpn/mpvpn
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2021
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 – ‘Add Admin’ Cross-Site Request Forgery (CSRF)
A Cross-Site Request Forgery (CSRF) vulnerability exists in FatPipe Networks WARP/IPVPN/MPVPN 10.2.2. An attacker can add an administrator account via CSRF.
Mitigation:
Implementing a security policy that requires the use of strong authentication and authorization for all administrative access, and enforcing the policy with technical controls, can help to mitigate the risk of CSRF attacks.