First published: Fri May 22 2020(Updated: )
An issue was discovered in Aviatrix Controller before 5.4.1066. A Controller Web Interface session token parameter is not required on an API call, which opens the application up to a Cross Site Request Forgery (CSRF) vulnerability for password resets.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Aviatrix Controllers | <5.4.1066 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-13416.
The severity level of CVE-2020-13416 is medium, with a severity value of 6.5.
The affected software is Aviatrix Controller versions up to and excluding 5.4.1066.
The CWE ID of CVE-2020-13416 is CWE-352.
The CSRF vulnerability on password resets can be exploited by performing unauthorized password resets through maliciously crafted requests.