SOCIFI Socifi Guest wifi as SAAS is affected by Cross Site Request Forgery (CSRF) via the Socifi wifi portal. The application does not contain a CSRF token and request validation. An attacker can Add/Modify any random user data by sending a crafted CSRF request.
History

Mon, 18 Nov 2024 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-352
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 12 Nov 2024 22:45:00 +0000

Type Values Removed Values Added
Description SOCIFI Socifi Guest wifi as SAAS is affected by Cross Site Request Forgery (CSRF) via the Socifi wifi portal. The application does not contain a CSRF token and request validation. An attacker can Add/Modify any random user data by sending a crafted CSRF request.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-11-12T00:00:00

Updated: 2024-11-18T18:12:42.859Z

Reserved: 2021-02-25T00:00:00

Link: CVE-2021-27701

cve-icon Vulnrichment

Updated: 2024-11-18T18:12:19.723Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-12T23:15:03.700

Modified: 2024-11-18T19:35:01.613

Link: CVE-2021-27701

cve-icon Redhat

No data.