vendor:
CLOKI Access Control
by:
LiquidWorm
6.8
CVSS
MEDIUM
Cross Site Request Forgery (CSRF)
352
CWE
Product Name: CLOKI Access Control
Affected Version From: 1.64
Affected Version To: 1.54
Patch Exists: NO
Related CWE:
CPE: a:zucchetti_axess:cloki_access_control
Platforms Tested: Start X3 (h02 build 4163), Start X1 (g01 build 2804), X1/X2/X3/X4/X7 Web Server
2021
Zucchetti Axess CLOKI Access Control 1.64 – Cross Site Request Forgery (CSRF)
Zucchetti Axess CLOKI Access Control 1.64 is vulnerable to Cross Site Request Forgery (CSRF). The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. These actions can be exploited to perform authentication detriment and account password change with administrative privileges if a logged-in user visits a malicious web site.
Mitigation:
The application should perform validity checks to verify the requests.