Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gxxf-h2fp-mgxp

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Castel NextGen DVR v1.0.0 is vulnerable to CSRF in all state-changing request. A __RequestVerificationToken is set by the web interface, and included in requests sent by web interface. However, this token is not verified by the application: the token can be removed from all requests and the request will succeed.

Castel NextGen DVR v1.0.0 is vulnerable to CSRF in all state-changing request. A __RequestVerificationToken is set by the web interface, and included in requests sent by web interface. However, this token is not verified by the application: the token can be removed from all requests and the request will succeed.

EPSS

Процентиль: 38%
0.00168
Низкий

Связанные уязвимости

CVSS3: 6.5
nvd
больше 5 лет назад

Castel NextGen DVR v1.0.0 is vulnerable to CSRF in all state-changing request. A __RequestVerificationToken is set by the web interface, and included in requests sent by web interface. However, this token is not verified by the application: the token can be removed from all requests and the request will succeed.

EPSS

Процентиль: 38%
0.00168
Низкий