Cross-site request forgery in Mailer - CVE-2022-20613

 

Cross-site request forgery in Mailer - CVE-2022-20613

Published: January 13, 2022


Vulnerability identifier: #VU59577
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20613
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform cross-site request forgery attacks.

The vulnerability exists due to the form validation method does not require POST requests. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website.


Affected software

Mailer
Oracle Communications Cloud Native Core Automated Test Suite

How to mitigate CVE-2022-20613

Install updates from vendor's website.

Mailer - update to 408.vd726a_1130320

External References

Related Security Bulletins