Cross Site Request Forgery in Tourism Management System Version 3.2
CVE-2022-30930
4.3MEDIUM
Summary
The Tourism Management System, specifically version 3.2, is susceptible to a Cross Site Request Forgery (CSRF) vulnerability. This security flaw allows attackers to manipulate the legitimate user's actions without their consent, posing a risk to the integrity and confidentiality of user data. This vulnerability emphasizes the necessity of implementing robust anti-CSRF mechanisms to safeguard web applications against unauthorized actions and potential data breaches.
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved