Cross-site request forgery in Lockable Resources - CVE-2020-2281

 

Cross-site request forgery in Lockable Resources - CVE-2020-2281

Published: September 23, 2020 / Updated: September 30, 2020


Vulnerability identifier: #VU47189
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-2281
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform cross-site request forgery attacks.

The vulnerability exists due to insufficient validation of the HTTP request origin. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website, such as reserve, unreserve, unlock and reset resources.


Affected software

Lockable Resources

How to mitigate CVE-2020-2281

Install update from vendor's website.

Lockable Resources - update to 2.9

External References

Related Security Bulletins