PeteReport Version 0.5 contains a Cross Site Request Forgery (CSRF) vulnerability allowing an attacker to trick users into deleting users, products, reports and findings on the application.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://fluidattacks.com/advisories/jett/ | issue tracking exploit third party advisory |
https://github.com/1modm/petereport/issues/34 | issue tracking exploit third party advisory |