First published: Fri Aug 25 2017(Updated: )
A Cross-Site Request Forgery issue was discovered in OSIsoft PI Web API versions prior to 2017 (1.9.0). The vulnerability allows cross-site request forgery (CSRF) attacks to occur when an otherwise-unauthorized cross-site request is sent from a browser the server has previously authenticated.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
OSIsoft PI API | =1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7926 is classified as a medium severity Cross-Site Request Forgery (CSRF) vulnerability.
CVE-2017-7926 allows unauthorized cross-site requests to be executed on behalf of authenticated users.
CVE-2017-7926 affects OSIsoft PI Web API versions prior to 1.9.0.
To mitigate CVE-2017-7926, upgrade to OSIsoft PI Web API version 1.9.0 or later.
CVE-2017-7926 enables Cross-Site Request Forgery (CSRF) attacks against users of the affected API.