Cross-Site Request Forgery in yetiforce
High severity
GitHub Reviewed
Published
Jan 27, 2022
to the GitHub Advisory Database
•
Updated Feb 3, 2023
Description
Published by the National Vulnerability Database
Jan 24, 2022
Reviewed
Jan 25, 2022
Published to the GitHub Advisory Database
Jan 27, 2022
Last updated
Feb 3, 2023
Versions of yetiforce 6.3.0 and prior are subject to privilege escalation via a cross site request forgery bug. This allows an attacker to create a new admin account even with SameSite: Strict enabled. This vulnerability can be exploited by any user on the system including guest users.
References