Engelsystem before commit hash 2e28336 allows CSRF.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://github.com/MyIgel/engelsystem/commit/2e28336818183e2c63c8015fb476bc01c822f50a | third party advisory patch |
https://github.com/engelsystem/engelsystem/issues/494 | third party advisory |