CODESYS Automation Server before 1.16.0 allows cross-site request forgery (CSRF).
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://customers.codesys.com/index.php | permissions required vendor advisory |
https://www.codesys.com/security/security-reports.html | vendor advisory |
https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=14638&token=30b75ee95d0d94527894dfd8cdc5432575a8eff8&download= | vendor advisory |