CSRF in the /login URI in BlueOnyx 5209R allows an attacker to access the dashboard and perform scraping or other analysis.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://gist.github.com/CyberSecurityUP/26c5b032897630fe8407da4a8ef216d4 | third party advisory exploit |
https://www.blueonyx.it/news/278/15/5209R5210R-YUM-Updates/ | release notes vendor advisory |
https://devel.blueonyx.it/trac/changeset/4034/ | patch vendor advisory |