CVE-2013-0144: CSRF
Cross-site request forgery (CSRF) vulnerability in cgi-bin/createuser.cgi on QNAP VioStor NVR devices with firmware 4.0.3 allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts via a NEW USER action.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0144?
CVE-2013-0144 is classified as a medium severity vulnerability due to its potential for unauthorized administrative access.
How do I fix CVE-2013-0144?
To mitigate CVE-2013-0144, update the firmware of QNAP VioStor NVR devices to a version later than 4.0.3 that addresses this vulnerability.
Who is affected by CVE-2013-0144?
CVE-2013-0144 affects administrators using QNAP VioStor NVR devices with firmware version 4.0.3.
What type of attack does CVE-2013-0144 enable?
CVE-2013-0144 enables remote attackers to perform cross-site request forgery (CSRF) attacks to hijack administrative actions.
What products are impacted by CVE-2013-0144?
CVE-2013-0144 specifically impacts QNAP Viostor Network Video Recorder devices running firmware version 4.0.3.