Cross-Site Request Forgery in Jorani by Benjamin BALET
CVE-2022-34134

8.8HIGH

Key Information:

Vendor

Jorani

Status
Vendor
CVE Published:
28 June 2022

What is CVE-2022-34134?

Jorani version 1.0 contains a vulnerability that can be exploited through Cross-Site Request Forgery (CSRF) in the Users controller. An attacker can trick a victim into executing unwanted actions within the application. This can potentially lead to unauthorized access or manipulation of user accounts. Proper measures should be taken to mitigate this risk.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.