PeteReport Version 0.5 contains a Cross Site Request Forgery (CSRF) vulnerability allowing an attacker to trick users into deleting users, products, reports and findings on the application.
References
Link | Resource |
---|---|
https://fluidattacks.com/advisories/jett/ | Exploit Issue Tracking Third Party Advisory |
https://github.com/1modm/petereport/issues/34 | Exploit Issue Tracking Third Party Advisory |
Configurations
Information
Published : 2022-03-03 14:15
Updated : 2022-03-10 07:08
NVD link : CVE-2022-23052
Mitre link : CVE-2022-23052
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
petereport_project
- petereport