Cross-Site Request Forgery in Online Banquet Booking System by Online Banquet
CVE-2022-28992
8.8HIGH
Summary
A Cross-Site Request Forgery vulnerability exists in the Online Banquet Booking System v1.0, allowing malicious actors to exploit the system via a crafted POST request. This vulnerability can enable attackers to change admin credentials without proper authentication, potentially compromising the integrity and security of the application and its users.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved