CVE-2019-12273: CSRF
Published Dec 31, 2019
·Updated
DISPUTED OutSystems Platform 10 through 11 allows ImageResourceDetail.aspx CSRF for content modifications and file uploads. NOTE: The product is self-hosted by the customer, even though it has a .outsystemsenterprise.com domain name.) NOTE: The vendor claims that the independent researcher created the report without any type of validation and that no such vulnerability exists.
Affected Software
1 affected component
Outsystems OutSystems>=10<=11
Event History
Dec 31, 2019
CVE Published
via MITRE·02:16 PM
Data Sourced
via MITRE·02:16 PM
Description
Disputed
03:15 PM
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
CVE-2019-12273.
2
Is this vulnerability considered high severity?
No, it is considered medium severity with a CVSS score of 6.5.
3
Which version of OutSystems Platform is affected by this vulnerability?
OutSystems Platform version 10 through 11 are affected.
4
What type of attack does this vulnerability allow?
This vulnerability allows for Cross-Site Request Forgery (CSRF) attacks on ImageResourceDetail.aspx.
5
How can this vulnerability be exploited?
An attacker can exploit this vulnerability to perform content modifications and file uploads on OutSystems Platform.