CVE-2023-4659: Cross-Site Request Forgery in Free5Gc
Cross-Site Request Forgery vulnerability, whose exploitation could allow an attacker to perform different actions on the platform as an administrator, simply by changing the token value to "admin". It is also possible to perform POST, GET and DELETE requests without any token value. Therefore, an unprivileged remote user is able to create, delete and modify users within theapplication.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-4659?
CVE-2023-4659 is a Cross-Site Request Forgery vulnerability that allows an attacker to perform different actions on the platform as an administrator.
How does CVE-2023-4659 work?
CVE-2023-4659 allows an attacker to change the token value to "admin", enabling them to perform actions as an administrator.
What is the severity of CVE-2023-4659?
CVE-2023-4659 has a severity rating of 9.8 (Critical).
How can I fix CVE-2023-4659?
To fix CVE-2023-4659, ensure that the token value is properly validated and authenticated before allowing any actions on the platform.
Is there any additional information about CVE-2023-4659?
For more information about CVE-2023-4659, you can refer to the following link: [Cross-Site Request Forgery Free5GC](https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-request-forgery-free5gc).