CVE-2022-46491

MEDIUM WAF: Low
CVSS 6.5 Published: 2022-12-22
CWE-352 CWE-352

A Cross-Site Request Forgery (CSRF) vulnerability in the Add Administrator function of the default version of nbnbk allows attackers to arbitrarily add Administrator accounts.

WAF Coverage Analysis

Cross-Site Request Forgery (CSRF) Low WAF Coverage

OWASP: A01:2021 Broken Access Control

Cross-Site Request Forgery (CSRF) Low WAF Coverage

OWASP: A01:2021 Broken Access Control

Affected Software

VendorProductVersion
nbnbk_projectnbnbk-

References

  • github.com (Exploit, Issue Tracking, Third Party Advisory)
Back to CVE Database