Cross-Site Request Forgery in Hyland OnBase Product
CVE-2020-25252
8.8HIGH
What is CVE-2020-25252?
An issue was discovered in Hyland OnBase versions up to 20.3.10.1000 that allows an attacker to exploit CSRF vulnerabilities. These vulnerabilities permit unauthorized actions by leveraging default credentials, specifically the wstinol password associated with the manager or hsi accounts. This enables an attacker to log in as an authenticated user and perform actions without consent, thereby compromising application integrity.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved