SmodBIP is vulnerable to Cross-Site Request Forgery, that could be used to induce logged in users to perform unintended actions, including creation of additional accounts with administrative privileges.
This issue affects all versions of SmodBIP. SmodBIP is no longer maintained and the vulnerability will not be fixed.
References
Link | Resource |
---|---|
https://cert.pl/en/posts/2023/10/CVE-2023-4837/ | Third Party Advisory |
https://cert.pl/posts/2023/10/CVE-2023-4837/ | Third Party Advisory |
https://smod.pl/ | Product |
https://cert.pl/en/posts/2023/10/CVE-2023-4837/ | Third Party Advisory |
https://cert.pl/posts/2023/10/CVE-2023-4837/ | Third Party Advisory |
https://smod.pl/ | Product |
Configurations
History
21 Nov 2024, 08:36
Type | Values Removed | Values Added |
---|---|---|
References | () https://cert.pl/en/posts/2023/10/CVE-2023-4837/ - Third Party Advisory | |
References | () https://cert.pl/posts/2023/10/CVE-2023-4837/ - Third Party Advisory | |
References | () https://smod.pl/ - Product |
21 Mar 2024, 02:49
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-10-10 10:15
Updated : 2024-11-21 08:36
NVD link : CVE-2023-4837
Mitre link : CVE-2023-4837
CVE.ORG link : CVE-2023-4837
JSON object : View
Products Affected
smod
- smodbip
CWE
CWE-352
Cross-Site Request Forgery (CSRF)