vendor:
GR10/GR25/GR30/GR50 GNSS
by:
Gjoko 'LiquidWorm' Krstic
6.8
CVSS
MEDIUM
Cross-Site Request Forgery
352
CWE
Product Name: GR10/GR25/GR30/GR50 GNSS
Affected Version From: 1.00.395
Affected Version To: 4.30.063
Patch Exists: NO
Related CWE: N/A
CPE: a:leica_geosystems:gr10/gr25/gr30/gr50_gnss:4.30.063
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WindowsCE
2018
Leica Geosystems GR10/GR25/GR30/GR50 GNSS 4.30.063 Cross-Site Request Forgery
The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.
Mitigation:
Implementing a security policy that prohibits the use of untrusted websites and implementing a secure authentication mechanism.