MEDIUM🇬🇧 English

CVE-2026-31014

CVSS 6.3v3.1pub. 2026-04-21upd. 2026-04-23

Dovestones Softwares AD Self Update <4.0.0.5 jest podatny na CSRF. Zaatakowany endpoint przetwarzać żądania zmieniające stan bez wymagania tokenu CSRF lub równoważnej ochrony. Endpoint akceptuje requesty application/x-www-form-urlencoded, a oryginalne żądanie POST można przekonwertować na GET, zachowując możliwość aktualizacji szczegółów użytkownika. Umożliwia to atakującemu stworzenie złośliwego żądania, które odwiedzone przez uwierzytelnionego użytkownika może modyfikować informacje konta bez jego zgody.

Pokaż oryginał (EN)

Dovestones Softwares AD Self Update <4.0.0.5 is vulnerable to Cross Site Request Forgery (CSRF). The affected endpoint processes state-changing requests without requiring a CSRF token or equivalent protection. The endpoint accepts application/x-www-form-urlencoded requests, and an originally POST-based request can be converted to a GET request while still successfully updating user details. This allows an attacker to craft a malicious request that, when visited by an authenticated user, can modify user account information without their consent.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
  • Dovestones Ad Self Update

    APP
    Dovestones
    < 4.0.0.5
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2015-8267CRITICAL10.0PL ✓ten sam vendor

Nieautoryzowany reset hasła w Dovestones AD Self Password Reset

CVE-2026-31013MEDIUM6.1ten sam vendor

Oprogramowanie Dovestones Softwares ADPhonebook w wersji poniżej 4.0.1.1 zawiera lukę reflected XSS w parametr...