Vulnerability Description
Various Vembu products allow an attacker to execute a (non-blind) http-only Cross Site Request Forgery (Other products or versions of products in this family may be affected too.)
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vembu | Bdr Suite | < 4.2.0 |
| Vembu | Offsite Dr | 4.2.0 |
Related Weaknesses (CWE)
References
- https://csirt.divd.nl/2021/05/11/Vembu-zero-days/Third Party Advisory
- https://csirt.divd.nl/cases/DIVD-2020-00011/Third Party Advisory
- https://csirt.divd.nl/cves/CVE-2021-26474/Third Party Advisory
- https://www.wbsec.nl/vembuThird Party Advisory
- https://csirt.divd.nl/2021/05/11/Vembu-zero-days/Third Party Advisory
- https://csirt.divd.nl/cases/DIVD-2020-00011/Third Party Advisory
- https://csirt.divd.nl/cves/CVE-2021-26474/Third Party Advisory
- https://www.wbsec.nl/vembuThird Party Advisory
FAQ
What is CVE-2021-26474?
CVE-2021-26474 is a vulnerability with a CVSS score of 8.6 (HIGH). Various Vembu products allow an attacker to execute a (non-blind) http-only Cross Site Request Forgery (Other products or versions of products in this family may be affected too.)
How severe is CVE-2021-26474?
CVE-2021-26474 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-26474?
Check the references section above for vendor advisories and patch information. Affected products include: Vembu Bdr Suite, Vembu Offsite Dr.