An issue was discovered in Logitech Options. The OAuth 2.0 state parameter was not properly validated. This leaves applications vulnerable to CSRF attacks during authentication and authorization operations.
Solution:
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://support.logi.com/hc/en-us/articles/360025297893 | vendor advisory |