A vulnerability was found in MRCMS 3.1.2. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Multiple endpoints might be affected.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://vuldb.com/?id.307428 | third party advisory vdb entry |
https://vuldb.com/?ctiid.307428 | permissions required signature vdb entry |
https://vuldb.com/?submit.563555 | third party advisory vdb entry |
https://github.com/bdkuzma/vuln/issues/8 | issue tracking third party advisory exploit |