First published: Thu Oct 13 2022(Updated: )
RPCMS v3.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily change the password of any account.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Runit | =3.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-41474 is classified as a high severity vulnerability due to its impact on user account security.
To fix CVE-2022-41474, upgrade RPCMS to the latest version that addresses the CSRF vulnerability.
CVE-2022-41474 allows an attacker to arbitrarily change the password of any account via Cross-Site Request Forgery.
RPCMS version 3.0.2 is the only affected version regarding CVE-2022-41474.
Currently, implementing proper CSRF protections and monitoring user actions may serve as temporary workarounds for CVE-2022-41474.