Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37244
HistorySep 23, 2022 - 4:56 a.m.

Cross-Site Request Forgery (CSRF)

2022-09-2304:56:33
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14
rdiffweb
vulnerability
pref_notification.py
csrf
email
attack

EPSS

0.001

Percentile

21.4%

rdiffweb is vulnerable to cross-site request forgery. The vulnerability exists because the render_prefs_panel function in pref_notification.py does not properly handle the password_form and profile_form attributes, allowing an attacker to change the email ID of the user by redirecting to the malicious urls.

EPSS

0.001

Percentile

21.4%