Cross-Site Request Forgery Vulnerability in Softing AG OPC Toolbox
CVE-2021-29660
8.8HIGH
What is CVE-2021-29660?
A Cross-Site Request Forgery (CSRF) vulnerability exists in the en/cfg_setpwd.html component of Softing AG's OPC Toolbox, which could allow an attacker to reset the administrative password. This occurs when the Administrator is tricked into visiting a specially crafted URL that is controlled by the attacker. This flaw could compromise the security of the system by enabling unauthorized access to administrative functionalities.
