mirror of
https://github.com/0xMarcio/cve.git
synced 2026-06-05 06:38:06 +02:00
18 lines
760 B
Markdown
18 lines
760 B
Markdown
### [CVE-2020-13416](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13416)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
An issue was discovered in Aviatrix Controller before 5.4.1066. A Controller Web Interface session token parameter is not required on an API call, which opens the application up to a Cross Site Request Forgery (CSRF) vulnerability for password resets.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://docs.aviatrix.com/HowTos/security_bulletin_article.html#csrf-on-password-reset
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|