CVE Published: 10/10/2023 |
CVE Updated: 18/09/2024 |
CVE Year: 2023 Source: CERT-PL |
Vendor: Jan Syski |
Product: SmodBIP Status : PUBLISHED
CVE-2023-4837 Description
SmodBIP is vulnerable to Cross-Site Request Forgery, that could be used to induce logged in users to perform unintended actions, including creation of additional accounts with administrative privileges.
This issue affects all versions of SmodBIP. SmodBIP is no longer maintained and the vulnerability will not be fixed.
Metrics
CVSS Version: 3.1 |
Base Score: 8.8 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H