Cross-Site Request Forgery Vulnerability in NSA Emissary Product
CVE-2021-32096
8.8HIGH
What is CVE-2021-32096?
The ConsoleAction component in NSA Emissary version 5.9.0 is susceptible to Cross-Site Request Forgery, enabling attackers to inject arbitrary Ruby code via the CONSOLE_COMMAND_STRING parameter. This vulnerability poses serious risks as it allows potential malicious actors to execute unauthorized commands, leading to compromised system integrity and unauthorized actions within the application.
