CVE-2021-41764
Summary
| CVE | CVE-2021-41764 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-09-29 20:15:00 UTC |
| Updated | 2021-10-03 00:56:00 UTC |
| Description | A cross-site request forgery (CSRF) vulnerability exists in Streama up to and including v1.10.3. The application does not have CSRF checks in place when performing actions such as uploading local files. As a result, attackers could make a logged-in administrator upload arbitrary local files via a CSRF attack and send them to the attacker. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Streama Project | Streama | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Streama-Exploit.html · GitHub | MISC | gist.github.com | |
| GitHub - streamaserver/streama: Self hosted streaming media server. https://docs.streama-project.com/ | MISC | github.com | |
| Streama Vulnerability · GitHub | MISC | gist.github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.