SmodBIP is vulnerable to Cross-Site Request Forgery, that could be used to induce logged in users to perform unintended actions, including creation of additional accounts with administrative privileges. This issue affects all versions of SmodBIP. SmodBIP is no longer maintained and the vulnerability will not be fixed.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://cert.pl/posts/2023/10/CVE-2023-4837/ | third party advisory |
https://cert.pl/en/posts/2023/10/CVE-2023-4837/ | third party advisory |
https://smod.pl/ | product |