CVE-2019-12273

OutSystems Platform 10 through 11 allows ImageResourceDetail.aspx CSRF for content modifications and file uploads. NOTE: The product is self-hosted by the customer, even though it has a *.outsystemsenterprise.com domain name.) NOTE: The vendor claims that the independent researcher created the report without any type of validation and that no such vulnerability exists
References
Link Resource
https://cxsecurity.com/issue/WLB-2019050242 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:outsystems:outsystems:*:*:*:*:*:*:*:*

History

07 Nov 2023, 03:03

Type Values Removed Values Added
Summary ** DISPUTED ** OutSystems Platform 10 through 11 allows ImageResourceDetail.aspx CSRF for content modifications and file uploads. NOTE: The product is self-hosted by the customer, even though it has a *.outsystemsenterprise.com domain name.) NOTE: The vendor claims that the independent researcher created the report without any type of validation and that no such vulnerability exists. OutSystems Platform 10 through 11 allows ImageResourceDetail.aspx CSRF for content modifications and file uploads. NOTE: The product is self-hosted by the customer, even though it has a *.outsystemsenterprise.com domain name.) NOTE: The vendor claims that the independent researcher created the report without any type of validation and that no such vulnerability exists

Information

Published : 2019-12-31 15:15

Updated : 2024-08-05 00:15


NVD link : CVE-2019-12273

Mitre link : CVE-2019-12273

CVE.ORG link : CVE-2019-12273


JSON object : View

Products Affected

outsystems

  • outsystems
CWE
CWE-352

Cross-Site Request Forgery (CSRF)