CVE-2020-21989
Summary
| CVE | CVE-2020-21989 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-27 18:15:00 UTC |
| Updated | 2021-05-06 14:05:00 UTC |
| Description | HomeAutomation 3.3.2 is affected by Cross Site Request Forgery (CSRF). The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Homeautomation Project | Homeautomation | 3.3.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Zero Science Lab » HomeAutomation v3.3.2 CSRF Add Admin Exploit | MISC | www.zeroscience.mk | |
| HomeAutomation 3.3.2 - Cross-Site Request Forgery (Add Admin) - PHP webapps Exploit | EXPLOIT-DB | www.exploit-db.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.