An issue was discovered in Quadbase ExpressDashboard (EDAB) 7 Update 9. It allows CSRF. An attacker may be able to trick an authenticated user into changing the email address associated with their account.
References
Link | Resource |
---|---|
https://c41nc.co.uk/cve-2020-24982/ | Exploit Third Party Advisory |
Configurations
Information
Published : 2021-03-15 11:15
Updated : 2021-05-21 09:25
NVD link : CVE-2020-24982
Mitre link : CVE-2020-24982
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
quadbase
- espressdashboard