First published: Wed Dec 07 2022(Updated: )
A Cross-Site Request Forgery (CSRF) in the Administrator List of MetInfo v7.7 allows attackers to arbitrarily add Super Administrator account.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Metinfo Metinfo | =7.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-44849 is a Cross-Site Request Forgery (CSRF) vulnerability in the Administrator List of MetInfo v7.7.
CVE-2022-44849 has a severity score of 8.8, which is considered high.
CVE-2022-44849 allows attackers to arbitrarily add a Super Administrator account in MetInfo v7.7.
Yes, MetInfo v7.7 is the only affected software.
To fix CVE-2022-44849, it is recommended to update MetInfo to a version that has patched this vulnerability.