CVE-2021-29054

Certain Papoo products are affected by: Cross Site Request Forgery (CSRF) in the admin interface. This affects Papoo CMS Light through 21.02 and Papoo CMS Pro through 6.0.1. The impact is: gain privileges (remote).
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:papoo:papoo:*:*:*:*:pro:*:*:*
cpe:2.3:a:papoo:papoo:*:*:*:*:light:*:*:*

History

21 Nov 2024, 06:00

Type Values Removed Values Added
References () https://github.com/raginx/security/blob/main/rADV-2021-01.txt - Third Party Advisory () https://github.com/raginx/security/blob/main/rADV-2021-01.txt - Third Party Advisory
References () https://packetstormsecurity.com/files/162077/Papoo-CMS-Cross-Site-Request-Forgery.html - Third Party Advisory, VDB Entry () https://packetstormsecurity.com/files/162077/Papoo-CMS-Cross-Site-Request-Forgery.html - Third Party Advisory, VDB Entry
References () https://www.papoo.de/achtung---sicherheitsfeature-bitte-aktivieren.html - Patch, Vendor Advisory () https://www.papoo.de/achtung---sicherheitsfeature-bitte-aktivieren.html - Patch, Vendor Advisory

Information

Published : 2021-04-13 06:15

Updated : 2024-11-21 06:00


NVD link : CVE-2021-29054

Mitre link : CVE-2021-29054

CVE.ORG link : CVE-2021-29054


JSON object : View

Products Affected

papoo

  • papoo
CWE
CWE-352

Cross-Site Request Forgery (CSRF)