Cross-site Request Forgery Vulnerability in HCL Connections
CVE-2021-27758
4.3MEDIUM
Summary
A security vulnerability exists in the login form of HCL Connections that allows attackers to exploit Cross-site Request Forgery (CSRF). This vulnerability can lead to user accounts being locked after repeated unauthorized login attempts, preventing legitimate users from accessing their accounts. It highlights the importance of implementing robust security measures to protect against CSRF attacks.
Affected Version(s)
HCL BigFix Inventory 9.x
HCL BigFix Inventory 10.x
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved