Cross-Site Request Forgery Affecting Open OnDemand by OSU
CVE-2020-36247
8.8HIGH
What is CVE-2020-36247?
Open OnDemand versions prior to 1.5.7 and 1.6.x versions before 1.6.22 are vulnerable to Cross-Site Request Forgery (CSRF), which allows attackers to trick users into executing unwanted actions on a web application in which they are authenticated. This vulnerability may lead to unauthorized commands being executed in the context of the user's session, potentially compromising user data and application integrity.
