An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows CSRF if the attacker uses GET where POST was intended.
References
Link | Resource |
---|---|
https://tvrbk.github.io/cve/2021/03/09/brXM.html | Exploit Third Party Advisory |
Configurations
Information
Published : 2021-03-11 11:15
Updated : 2021-03-18 05:56
NVD link : CVE-2020-14989
Mitre link : CVE-2020-14989
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
bloomreach
- experience_manager