First published: Fri Nov 16 2018(Updated: )
School Attendance Monitoring System 1.0 has CSRF via /user/user/edit.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Janobe School Attendance Monitoring System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18797 has a medium severity rating due to its CSRF vulnerability that can be exploited to perform unauthorized actions.
To fix CVE-2018-18797, implement anti-CSRF tokens in forms and ensure that user requests are validated.
CVE-2018-18797 affects version 1.0 of the School Attendance Monitoring System.
CVE-2018-18797 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
CVE-2018-18797 can be exploited to carry out unauthorized actions on behalf of an authenticated user.