First published: Fri Nov 16 2018(Updated: )
School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Janobe School Attendance Monitoring System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18799 is considered a medium severity vulnerability due to its ability to facilitate cross-site request forgery (CSRF) attacks.
To fix CVE-2018-18799, implement CSRF tokens in forms and validate them server-side to prevent unauthorized actions.
CVE-2018-18799 affects version 1.0 of the School Attendance Monitoring System.
CVE-2018-18799 allows attackers to exploit CSRF vulnerabilities which can result in unauthorized actions being performed on behalf of a user.
Yes, there are known exploits for CVE-2018-18799 that demonstrate how an attacker can execute CSRF attacks against the system.