Cross Site Request Forgery in Tourism Management System Version 3.2
CVE-2022-30930

4.3MEDIUM

Key Information:

Vendor
PHPgurukul
Vendor
CVE Published:
14 June 2022

Summary

The Tourism Management System, specifically version 3.2, is susceptible to a Cross Site Request Forgery (CSRF) vulnerability. This security flaw allows attackers to manipulate the legitimate user's actions without their consent, posing a risk to the integrity and confidentiality of user data. This vulnerability emphasizes the necessity of implementing robust anti-CSRF mechanisms to safeguard web applications against unauthorized actions and potential data breaches.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.