First published: Thu Apr 29 2021(Updated: )
Cross Site Request Forgery (CSRF) in Rukovoditel v2.8.3 allows attackers to create an admin user with an arbitrary credentials.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Rukovoditel Rukovoditel | =2.8.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-30224 is a Cross Site Request Forgery (CSRF) vulnerability in Rukovoditel v2.8.3 that allows attackers to create an admin user with arbitrary credentials.
The severity of CVE-2021-30224 is high with a CVSS score of 8.8.
To exploit CVE-2021-30224, an attacker can perform a Cross Site Request Forgery (CSRF) attack to create an admin user with arbitrary credentials.
To fix CVE-2021-30224, it is recommended to update Rukovoditel to a version that includes the necessary security patches.
Yes, you can find references for CVE-2021-30224 at the following links: [Reference 1](https://forum.rukovoditel.net/viewtopic.php?f=19&t=2760), [Reference 2](https://gist.github.com/victomteng1997/d5f2db1d37aed5792c28685068ec41e2)