First published: Wed Dec 16 2020(Updated: )
Lack of an anti-CSRF token in the entire administrative interface in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to force an administrator to execute external POST requests by visiting a malicious website.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Epson Eps Tse Server 8 Firmware | =21.0.11 | |
EPSON EPS TSE Server 8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-28931 is a vulnerability in EPSON EPS TSE Server 8 (21.0.11) that allows an unauthenticated attacker to force an administrator to execute external POST requests.
CVE-2020-28931 has a severity score of 8.8, which is considered high.
The affected software for CVE-2020-28931 is EPSON EPS TSE Server 8 (21.0.11).
An attacker can exploit CVE-2020-28931 by visiting a malicious website, which tricks an administrator into executing external POST requests.
No, EPSON EPS TSE Server 8 is not vulnerable to CVE-2020-28931.