CVE-2020-28931: CSRF
Published Dec 16, 2020
·Updated
Lack of an anti-CSRF token in the entire administrative interface in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to force an administrator to execute external POST requests by visiting a malicious website.
Affected Software
2 affected components
Epson Eps Tse Server 8 Firmware=21.0.11
Epson EPS TSE Server 8
Event History
Dec 16, 2020
CVE Published
via MITRE·08:28 PM
Data Sourced
via MITRE·08:28 PM
Description
Frequently Asked Questions
1
What is CVE-2020-28931?
CVE-2020-28931 is a vulnerability in EPSON EPS TSE Server 8 (21.0.11) that allows an unauthenticated attacker to force an administrator to execute external POST requests.
2
How severe is CVE-2020-28931?
CVE-2020-28931 has a severity score of 8.8, which is considered high.
3
What is the affected software for CVE-2020-28931?
The affected software for CVE-2020-28931 is EPSON EPS TSE Server 8 (21.0.11).
4
How can an attacker exploit CVE-2020-28931?
An attacker can exploit CVE-2020-28931 by visiting a malicious website, which tricks an administrator into executing external POST requests.
5
Is EPSON EPS TSE Server 8 vulnerable to CVE-2020-28931?
No, EPSON EPS TSE Server 8 is not vulnerable to CVE-2020-28931.