First published: Fri May 20 2022(Updated: )
A Cross-Site Request Forgery (CSRF) in Online Banquet Booking System v1.0 allows attackers to change admin credentials via a crafted POST request.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Phpgurukul Online Banquet Booking System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-28992 is high with a severity value of 8.8.
CVE-2022-28992 is a Cross-Site Request Forgery (CSRF) vulnerability in Online Banquet Booking System v1.0.
Attackers can change admin credentials by exploiting the CSRF vulnerability in Online Banquet Booking System v1.0 through a crafted POST request.
To fix CVE-2022-28992, it is recommended to apply the latest patch or update provided by Phpgurukul Online Banquet Booking System.
You can find more information about CVE-2022-28992 at the following reference: [Online-Banquet-Booking-System-1.0-Cross-Site-Request-Forgery](https://packetstormsecurity.com/files/166587/Online-Banquet-Booking-System-1.0-Cross-Site-Request-Forgery.html)