vendor:
SOYAL Access Control System
by:
LiquidWorm
8.8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: SOYAL Access Control System
Affected Version From: AR-727 i/CM - F/W: 5.0
Affected Version To: AR331/725E - F/W: 4.2
Patch Exists: NO
Related CWE: N/A
CPE: a:soyal_technology:soyal_access_control_system
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: SOYAL Technology WebServer 2.0, SOYAL Serial Device Server 4.03A, SOYAL Serial Device Server 4.01n, SOYAL Serial Device Server 3.07n
2021
SOYAL Biometric Access Control System 5.0 – ‘Change Admin Password’ CSRF
The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.
Mitigation:
The application should verify the requests before performing any action.