vendor:
ICEHRM
by:
Devansh Bordia
5.5
CVSS
MEDIUM
Cross-site Request Forgery (CSRF)
352
CWE
Product Name: ICEHRM
Affected Version From: 31.0.0.OS
Affected Version To: 31.0.0.OS
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
2022
ICEHRM 31.0.0.0S – Cross-site Request Forgery (CSRF) to Account Takeover
The application has an update password feature which has a CSRF vulnerability that allows an attacker to change the password of any arbitrary user leading to an account takeover.
Mitigation:
Implement CSRF protection mechanisms such as CSRF tokens in sensitive operations.