vendor:
TemaTres
by:
Pablo Santiago
7.5
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: TemaTres
Affected Version From: 3
Affected Version To: 3
Patch Exists: YES
Related CWE: 2019–14345
CPE: a:vocabularyserver:tematres:3.0
Platforms Tested: Windows 10
2019
TemaTres 3.0 — Cross-Site Request Forgery (Add Admin)
This exploit allows an attacker to add an admin user to the TemaTres 3.0 web application by bypassing authentication.
Mitigation:
Implement CSRF protection mechanisms to prevent unauthorized actions.